Skip to content
Fedora OpenSSH Serious Denial of Service and Heap Vulnerabilities Issues

Fedora OpenSSH Serious Denial of Service and Heap Vulnerabilities Issues

Linuxsecurity LinuxSecurity Advisories July 9, 2026

Improve GSS KEX algorithms documentation CVE-2026-55653: Fix double free in openssh DH-GEX client path during FIPS known- group validation that leads to client-side denial of service CVE-2026-55654: Fix heap out-of-bounds read during GSSAPI indicator cleanup due to missing NULL terminator CVE-2026-55655: Fix MITM of X11 forwarding via abstract UNIX socket pre-binding

* Tue Jul 7 2026 Dmitry Belyavskiy - 10.2p1-12 - Improve GSS KEX algorithms documentation Patches are submitted by [email protected] Resolves: rhbz#2241564 * Tue Jul 7 2026 Zoltan Fridrich - 10.2p1-11 - CVE-2026-55653: Fix double free in openssh DH-GEX client path during FIPS known-group validation that leads to client-side denial of service - CVE-2026-55654: Fix heap out-of-bounds read during GSSAPI indicator cleanup due to missing NULL terminator - CVE-2026-55655: Fix MITM of X11 forwarding via abstract UNIX socket pre-binding - Remove duplicate manpage entries from ssh(1) Resolves: rhbz#2442505

* Tue Jul 7 2026 Dmitry Belyavskiy - 10.2p1-12 - Improve GSS KEX algorithms documentation Patches are submitted by [email protected] Resolves: rhbz#2241564 * Tue Jul 7 2026 Zoltan Fridrich - 10.2p1-11 - CVE-2026-55653: Fix double free in openssh DH-GEX client path during FIPS known-group validation that leads to client-side denial of service - CVE-2026-55654: Fix heap out-of-bounds read during GSSAPI indicator cleanup due to missing NULL terminator - CVE-2026-55655: Fix MITM of X11 forwarding via abstract UNIX socket pre-binding - Remove duplicate manpage entries from ssh(1) Resolves: rhbz#2442505

[ 1 ] Bug #2241564 - KexAlgorithms accepts gss-* algorithms in certain cases, but it is completely unclear what this does [ 2 ] Bug #2442505 - 0043-openssh-8.7p1-ssh-manpage.patch introduces duplicates in documentation

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a80275b42d' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities