Junglewise Threat Intelligence

CVE-2026-55653: OpenSSH double free in DH-GEX client during FIPS validation

CVE-2026-55653 · Severity: medium · CVSS 4.3 · Published 2026-06-23

Technologies: Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 7, Openssh, Red Hat Enterprise Linux 6, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10. Vendors: Red Hat.

Executive brief

A vulnerability in OpenSSH's client software could allow a malicious server to crash the client application. This occurs when the client is running in FIPS mode and connects to a server that provides specifically crafted security parameters. While this primarily results in a service disruption (Denial of Service) for the user or automated process initiating the connection, it does not currently appear to allow for data theft or unauthorized access.

Technical details

A double free vulnerability exists in the `input_kex_dh_gex_group()` function within `kexgexc.c` of OpenSSH. When the client is operating in FIPS mode, it performs a known-group validation on server-supplied parameters. If this validation fails, the code jumps to a cleanup routine that frees BIGNUM objects (`p` and `g`) that have already been assigned to the `kex->dh` structure. A second free occurs during the subsequent teardown of the SSH state in `kex_free()`. This is most reliably triggered in non-fatal client flows like `ssh-keyscan`. Exploitation requires the client to negotiate `diffie-hellman-group-exchange-sha256` and receive attacker-controlled DH-GEX parameters. The primary impact is a crash (SIGABRT) of the client process.

Affected products

  • OpenSSH OpenSSH 9.9p1-22.el10_2 (Red Hat build)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9
  • Red Hat Red Hat Enterprise Linux 10
  • Red Hat Red Hat OpenShift Container Platform 4

Timeline

  • 2026-04-26: disclosed: Initial report to Red Hat Bugzilla
  • 2026-06-23: advisory: CVE published by NVD/Red Hat

References

Related threats