Logo
vulnerabilityCVE-2026-55653
Name
CVE-2026-55653
Source
NVD ( link)Debian ( link)
Description
A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
openssh
False Positive

Vulnerability Ratings#


4.3
CVSSv31
6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
9.9p2
Not Affected
buildroot
master
10.5p1
Not Affected
openwrt
master
10.4_p1-r2
Not Affected
openwrt
openwrt-25.12
10.3_p1-r1
Not Affected
yocto
kirkstone
8.9p1
Not Affected
yocto
scarthgap
9.6p1
Not Affected