Impact
A double free flaw exists in the Diffie‑Hellman Group Exchange path of OpenSSH. When an SSH client operating in FIPS mode validates attacker‑controlled DH‑GEX group parameters, the server can trigger a double free, causing the client process to terminate. The result is a denial of service that affects only the client side, potentially disrupting automated workflows that rely on SSH connectivity.
Affected Systems
Red Hat Enterprise Linux 10, 6, 7, 8, 9, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4 all ship an affected OpenSSH client. Any host in these families that runs OpenSSH in FIPS mode is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 reflects a medium severity, indicating a limited but non‑negligible impact. The EPSS score is not available, so the likelihood of exploitation is uncertain, but the vulnerability is exploitable by any malicious SSH server the client connects to. It is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. The attack vector is remote, originating from a compromised or malicious SSH server, and would require the client to engage in FIPS mode group validation to trigger the crash.
OpenCVE Enrichment