6.5
CVE-2026-55653
- EPSS 0.29%
- Veröffentlicht 23.06.2026 03:36:22
- Zuletzt bearbeitet 07.10.2026 03:16:59
- Erkennungen
Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Hardened Images Version -
Redhat ≫ Openshift Container Platform Version 4.0
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.213 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
|
| RedHat | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
|
CWE-415 Double Free
The product calls free() twice on the same memory address.
https://bugzilla.redhat.com/show_bug.cgi?id=2462351
https://access.redhat.com/errata/RHSA-2026:36759
https://access.redhat.com/security/cve/CVE-2026-55653
https://access.redhat.com/errata/RHSA-2026:47755
https://access.redhat.com/errata/RHSA-2026:47756
https://access.redhat.com/errata/RHSA-2026:47757
https://access.redhat.com/errata/RHSA-2026:54387
https://access.redhat.com/errata/RHSA-2026:58981
https://access.redhat.com/errata/RHSA-2026:76748
https://access.redhat.com/errata/RHSA-2026:76993