A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssh-askpassUpgrade openssh-cavsUpgrade pam_ssh_agent_authUpgrade opensshUpgrade openssh-serverUpgrade openssh-ldapUpgrade openssh-clientsUpgrade openssh-keycat | Aug 2, 2026 | Jul 29, 2026 |
| Amazon_linux_2023 | — | Upgrade pam_ssh_agent_authUpgrade openssh-server-debuginfoUpgrade openssh-debugsourceUpgrade openssh-sk-dummy-debuginfoUpgrade openssh-keycatUpgrade openssh-clients-debuginfoUpgrade openssh-sk-dummyUpgrade opensshUpgrade openssh-keycat-debuginfoUpgrade openssh-clientsUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-serverUpgrade openssh-debuginfo | Aug 10, 2026 | Jun 23, 2026 |
| Redhat_linux | — | Upgrade openssh-clients-debuginfoUpgrade openssh-server-debuginfoUpgrade openssh-debugsourceUpgrade openssh-cavs-debuginfoUpgrade openssh-keysign-debuginfoNo solution existsUpgrade openssh-serverUpgrade openssh-sk-dummy-debuginfoUpgrade pam_ssh_agent_authUpgrade openssh-askpassUpgrade openssh-cavsUpgrade openssh-ldapUpgrade pam_ssh_agent_auth-debuginfoUpgrade opensshUpgrade openssh-keycat-debuginfoUpgrade openssh-debuginfoUpgrade openssh-askpass-debuginfoUpgrade openssh-keysignUpgrade openssh-keycatUpgrade openssh-clientsUpgrade openssh-ldap-debuginfo | Jul 17, 2026 | Jun 22, 2026 |
| Rocky_linux | — | Upgrade openssh-cavsUpgrade opensshUpgrade openssh-server-debuginfoUpgrade openssh-debugsourceUpgrade openssh-debuginfoUpgrade openssh-serverUpgrade openssh-cavs-debuginfoUpgrade openssh-ldap-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-ldapUpgrade openssh-keycat-debuginfoUpgrade openssh-askpass-debuginfoUpgrade openssh-clientsUpgrade openssh-askpassUpgrade openssh-clients-debuginfoUpgrade openssh-keycatUpgrade pam_ssh_agent_auth | Aug 3, 2026 | Jul 30, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 3, 2026 | Jun 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub