Описание
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | deferred | 2026-06-29 |
| esm-infra-legacy/trusty | deferred | 2026-06-29 |
| esm-infra-legacy/xenial | deferred | 2026-06-29 |
| esm-infra/bionic | deferred | 2026-06-29 |
| esm-infra/focal | deferred | 2026-06-29 |
| fips-preview/jammy | deferred | 2026-06-29 |
| fips-updates/bionic | deferred | 2026-06-29 |
| fips-updates/focal | deferred | 2026-06-29 |
| fips-updates/jammy | deferred | 2026-06-29 |
| fips-updates/noble | deferred | 2026-06-29 |
Показывать по
| Релиз | Статус | Примечание |
|---|---|---|
| devel | ignored | |
| esm-apps/bionic | ignored | |
| esm-apps/focal | ignored | |
| esm-apps/jammy | ignored | |
| esm-apps/noble | ignored | |
| esm-apps/resolute | ignored | |
| jammy | ignored | |
| noble | ignored | |
| questing | ignored | |
| resolute | ignored |
Показывать по
EPSS
5 Medium
CVSS3
Связанные уязвимости
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.
Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux ...
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.
EPSS
5 Medium
CVSS3