CVE-2026-55653

EUVD-2026-38412
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 20.5%
Affected Products (NVD)
VendorProductVersion
openbsdopenssh
-
redhathardened_images
-
redhatopenshift_container_platform
4.0
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssh
bookworm
1:9.2p1-2+deb12u10
fixed
bookworm (security)
1:9.2p1-2+deb12u9
fixed
bullseye
1:8.4p1-5+deb11u3
fixed
bullseye (security)
1:8.4p1-5+deb11u7
fixed
forky
1:10.4p1-2
fixed
sid
1:10.4p1-4
fixed
trixie
1:10.0p1-7+deb13u4
fixed
trixie (security)
1:10.0p1-7+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssh
bionic
needs-triage
focal
needs-triage
jammy
not-affected
noble
not-affected
questing
not-affected
resolute
not-affected
trusty
needs-triage
xenial
needs-triage
openssh-ssh1
bionic
ignored
focal
ignored
jammy
ignored
noble
ignored
questing
ignored
resolute
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
openssh
RHEL 8
0:8.0p1-30.el8_10
fixed
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-askpass
RHEL 8
0:8.0p1-30.el8_10
fixed
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-cavs
RHEL 8
0:8.0p1-30.el8_10
fixed
openssh-clients
RHEL 8
0:8.0p1-30.el8_10
fixed
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-keycat
RHEL 8
0:8.0p1-30.el8_10
fixed
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-ldap
RHEL 8
0:8.0p1-30.el8_10
fixed
openssh-server
RHEL 8
0:8.0p1-30.el8_10
fixed
RHEL 9
0:9.9p1-9.el9_8
fixed
pam
RHEL 8
0:0.10.3-7.30.el8_10
fixed
RHEL 9
0:0.10.4-7.9.el9_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
openssh
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-clients
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-clients-debuginfo
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-debuginfo
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-debugsource
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-keycat
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-keycat-debuginfo
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-server
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-server-debuginfo
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-sk-dummy
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-sk-dummy-debuginfo
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
pam_ssh_agent_auth
Amazon Linux 2023
0:0.10.4-9.10.amzn2023.0.1
fixed
pam_ssh_agent_auth-debuginfo
Amazon Linux 2023
0:0.10.4-9.10.amzn2023.0.1
fixed