A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade opensshUpgrade pam_ssh_agent_authUpgrade openssh-serverUpgrade openssh-keycatUpgrade openssh-askpassUpgrade openssh-ldapUpgrade openssh-clientsUpgrade openssh-cavs | Aug 2, 2026 | Jul 29, 2026 |
| Amazon_linux_2023 | — | Upgrade openssh-sk-dummyUpgrade openssh-clients-debuginfoUpgrade openssh-keycat-debuginfoUpgrade openssh-keycatUpgrade openssh-server-debuginfoUpgrade openssh-clientsUpgrade pam_ssh_agent_authUpgrade openssh-debugsourceUpgrade opensshUpgrade openssh-sk-dummy-debuginfoUpgrade openssh-serverUpgrade openssh-debuginfoUpgrade pam_ssh_agent_auth-debuginfo | Aug 10, 2026 | Jun 23, 2026 |
| Redhat_linux | — | Upgrade openssh-keycat-debuginfoUpgrade openssh-debuginfoUpgrade openssh-keycatUpgrade openssh-ldapUpgrade openssh-askpassUpgrade openssh-cavsUpgrade openssh-ldap-debuginfoUpgrade opensshUpgrade openssh-debugsourceUpgrade openssh-cavs-debuginfoUpgrade openssh-keysignUpgrade openssh-askpass-debuginfoUpgrade openssh-clients-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-serverUpgrade pam_ssh_agent_authNo solution existsUpgrade openssh-sk-dummy-debuginfoUpgrade openssh-server-debuginfoUpgrade openssh-clientsUpgrade openssh-keysign-debuginfo | Jul 17, 2026 | Jun 22, 2026 |
| Rocky_linux | — | Upgrade openssh-clientsUpgrade pam_ssh_agent_authUpgrade openssh-keycatUpgrade openssh-debuginfoUpgrade openssh-clients-debuginfoUpgrade openssh-cavsUpgrade opensshUpgrade openssh-askpassUpgrade openssh-ldapUpgrade openssh-server-debuginfoUpgrade openssh-askpass-debuginfoUpgrade openssh-cavs-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-debugsourceUpgrade openssh-ldap-debuginfoUpgrade openssh-keycat-debuginfoUpgrade openssh-server | Aug 3, 2026 | Jul 30, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub