{
  "threat_severity" : "Moderate",
  "public_date" : "2026-06-22T23:17:43Z",
  "bugzilla" : {
    "description" : "openssh: Double free in Red Hat Enterprise Linux versions of OpenSSH DH-GEX client path during FIPS known-group validation leads to client-side denial of service",
    "id" : "2462351",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2462351"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-415",
  "details" : [ "A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).", "A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS)." ],
  "statement" : "This Moderate flaw in OpenSSH affects clients operating in FIPS mode when negotiating Diffie-Hellman Group Exchange (DH-GEX) with a malicious SSH server. While it can lead to client process termination, resulting in a denial of service, the impact is limited to availability and does not result in broader system compromise. In order to exploit this vulnerability the attacker needs to trick the user to connect to an untrusted malicious server or compromise the server first. The availability impact is considered Low as the only impacted process is the single run of the SSH client trying to connect to the malicious server.\nThis vulnerability affects only the OpenSSH versions shipped with Red Hat products.",
  "acknowledgement" : "This issue was discovered by In partnership with Red Hat (Aisle.com).",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "release_date" : "2026-07-30T00:00:00Z",
    "advisory" : "RHSA-2026:47757",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10.2",
    "package" : "openssh-0:9.9p1-25.el10_2"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-30T00:00:00Z",
    "advisory" : "RHSA-2026:47755",
    "cpe" : "cpe:/a:redhat:enterprise_linux:8",
    "package" : "openssh-0:8.0p1-30.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "release_date" : "2026-07-30T00:00:00Z",
    "advisory" : "RHSA-2026:47755",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8",
    "package" : "openssh-0:8.0p1-30.el8_10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-29T00:00:00Z",
    "advisory" : "RHSA-2026:47756",
    "cpe" : "cpe:/a:redhat:enterprise_linux:9",
    "package" : "openssh-0:9.9p1-9.el9_8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "release_date" : "2026-07-29T00:00:00Z",
    "advisory" : "RHSA-2026:47756",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9",
    "package" : "openssh-0:9.9p1-9.el9_8"
  }, {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-08T00:00:00Z",
    "advisory" : "RHSA-2026:36759",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "openssh-main-10.3p1-6.hum1"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-12T00:00:00Z",
    "advisory" : "RHSA-2026:54387",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/installer-rhel9:1786435483"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-12T00:00:00Z",
    "advisory" : "RHSA-2026:54387",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-rhel9:1786533529"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/installer-tp-rhel9:1787135742"
  }, {
    "product_name" : "Red Hat Update Infrastructure 5",
    "release_date" : "2026-08-24T00:00:00Z",
    "advisory" : "RHSA-2026:58981",
    "cpe" : "cpe:/a:redhat:rhui:5::el9",
    "package" : "rhui5/rhua-tp-rhel9:1787241260"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Affected",
    "package_name" : "openssh",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Affected",
    "package_name" : "openssh",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift/ose-rhel-coreos-8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift/ose-rhel-coreos-9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-55653\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-55653" ],
  "name" : "CVE-2026-55653",
  "mitigation" : {
    "value" : "To mitigate this issue, OpenSSH clients operating in FIPS mode should avoid negotiating the `diffie-hellman-group-exchange-sha256` key exchange algorithm. This can be achieved by explicitly listing allowed key exchange algorithms in the client's SSH configuration file (e.g., `/etc/ssh/ssh_config` or `~/.ssh/config`), ensuring `diffie-hellman-group-exchange-sha256` is *not* included. For example, to use a subset of common algorithms, you might configure:\n```\nKexAlgorithms curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group14-sha1\n```\n(Note: The above example `KexAlgorithms` list is illustrative and should be adjusted based on your environment's security requirements.)\nAdditionally, avoid using non-fatal client flows, such as `ssh-keyscan`, against untrusted SSH servers while FIPS mode is enabled. Changes to `ssh_config` will take effect for new SSH connections.",
    "lang" : "en:us"
  },
  "csaw" : false
}