A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attacker-controlled DH-GEX group parameters. Successful exploitation leads to client-side process termination, resulting in a Denial of Service (DoS).
The product calls free() twice on the same memory address.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Openssh | Openbsd | - (including) | - (including) |
| Hardened_images | Redhat | - (including) | - (including) |
| Openshift_container_platform | Redhat | 4.0 (including) | 4.0 (including) |
| Enterprise_linux | Redhat | 6.0 (including) | 6.0 (including) |
| Enterprise_linux | Redhat | 7.0 (including) | 7.0 (including) |
| Enterprise_linux | Redhat | 8.0 (including) | 8.0 (including) |
| Enterprise_linux | Redhat | 9.0 (including) | 9.0 (including) |
| Enterprise_linux | Redhat | 10.0 (including) | 10.0 (including) |
| Red Hat Enterprise Linux 10 | RedHat | openssh-0:9.9p1-25.el10_2 | * |
| Red Hat Enterprise Linux 8 | RedHat | openssh-0:8.0p1-30.el8_10 | * |
| Red Hat Enterprise Linux 8 | RedHat | openssh-0:8.0p1-30.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | openssh-0:9.9p1-9.el9_8 | * |
| Red Hat Enterprise Linux 9 | RedHat | openssh-0:9.9p1-9.el9_8 | * |
| Red Hat Hardened Images | RedHat | openssh-main-10.3p1-6.hum1 | * |
| Openssh-ssh1 | Ubuntu | devel | * |
| Openssh-ssh1 | Ubuntu | esm-apps/bionic | * |
| Openssh-ssh1 | Ubuntu | esm-apps/focal | * |
| Openssh-ssh1 | Ubuntu | esm-apps/jammy | * |
| Openssh-ssh1 | Ubuntu | esm-apps/noble | * |
| Openssh-ssh1 | Ubuntu | esm-apps/resolute | * |
| Openssh-ssh1 | Ubuntu | jammy | * |
| Openssh-ssh1 | Ubuntu | noble | * |
| Openssh-ssh1 | Ubuntu | questing | * |
| Openssh-ssh1 | Ubuntu | resolute | * |
| Openssh-ssh1 | Ubuntu | upstream | * |