A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssh-keycatUpgrade openssh-clientsUpgrade openssh-askpassUpgrade openssh-ldapUpgrade openssh-serverUpgrade openssh-cavsUpgrade pam_ssh_agent_authUpgrade openssh | Aug 2, 2026 | Jul 29, 2026 |
| Amazon_linux_2023 | — | Upgrade pam_ssh_agent_authUpgrade openssh-keycat-debuginfoUpgrade openssh-server-debuginfoUpgrade openssh-sk-dummyUpgrade openssh-clientsUpgrade openssh-keycatUpgrade openssh-clients-debuginfoUpgrade openssh-sk-dummy-debuginfoUpgrade openssh-debugsourceUpgrade opensshUpgrade openssh-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-server | Aug 10, 2026 | Jun 23, 2026 |
| Redhat_linux | — | Upgrade openssh-debugsourceUpgrade openssh-keysignUpgrade openssh-ldap-debuginfoUpgrade openssh-debuginfoUpgrade openssh-cavs-debuginfoUpgrade openssh-askpassUpgrade openssh-askpass-debuginfoUpgrade openssh-ldapUpgrade openssh-keycatUpgrade openssh-cavsUpgrade opensshUpgrade openssh-keycat-debuginfoUpgrade openssh-clientsNo solution existsUpgrade openssh-serverUpgrade pam_ssh_agent_authUpgrade openssh-keysign-debuginfoUpgrade openssh-sk-dummy-debuginfoUpgrade openssh-server-debuginfoUpgrade openssh-clients-debuginfoUpgrade pam_ssh_agent_auth-debuginfo | Jul 17, 2026 | Jun 22, 2026 |
| Rocky_linux | — | Upgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-server-debuginfoUpgrade openssh-askpass-debuginfoUpgrade openssh-serverUpgrade openssh-ldapUpgrade openssh-keycat-debuginfoUpgrade openssh-cavs-debuginfoUpgrade openssh-debugsourceUpgrade openssh-ldap-debuginfoUpgrade openssh-cavsUpgrade openssh-askpassUpgrade pam_ssh_agent_authUpgrade openssh-clientsUpgrade openssh-debuginfoUpgrade opensshUpgrade openssh-keycatUpgrade openssh-clients-debuginfo | Aug 3, 2026 | Jul 30, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub