Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55655

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.

Отчет

This is a Moderate severity flaw. The OpenSSH client in Red Hat Enterprise Linux is vulnerable to a local man-in-the-middle attack on X11 forwarding connections. Exploitation requires an attacker to have local unprivileged access on the client system and for X11 forwarding to be explicitly enabled and in use, which is not a default configuration. The attack can compromise the confidentiality of forwarded X11 traffic. This vulnerability doesn't affect the upstream OpenSSH versions and is restricted to the versions as shipped with Red Hat Enterprise Linux.

Меры по смягчению последствий

To mitigate this issue, disable X11 forwarding on OpenSSH clients when it is not required. This can be achieved by avoiding the use of -X or -Y options when invoking ssh, or by setting ForwardX11 no in the SSH client configuration file (~/.ssh/config or /etc/ssh/ssh_config). Disabling X11 forwarding will prevent the client from attempting to establish X11 connections, thereby removing the attack vector.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10opensshAffected
Red Hat Enterprise Linux 6opensshAffected
Red Hat Enterprise Linux 7opensshAffected
Red Hat Enterprise Linux 8opensshAffected
Red Hat Enterprise Linux 9opensshAffected
Red Hat OpenShift Container Platform 4rhcosUnder investigation
Red Hat Hardened Imagesopenssh-main-10.3p1-6.hum1FixedRHSA-2026:3675908.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-923
https://bugzilla.redhat.com/show_bug.cgi?id=2462250openssh: Local MITM of X11 forwarding via abstract UNIX socket pre-binding in Red Hat Enterprise Linux OpenSSH client versions

EPSS

Процентиль: 0%
0.00088
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
около 1 месяца назад

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.

CVSS3: 5
nvd
около 1 месяца назад

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.

msrc
около 1 месяца назад

Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions

CVSS3: 5
debian
около 1 месяца назад

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux ...

CVSS3: 5
github
около 1 месяца назад

A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.

EPSS

Процентиль: 0%
0.00088
Низкий

5 Medium

CVSS3