A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade openssh-keycatUpgrade openssh-serverUpgrade openssh-ldapUpgrade openssh-clientsUpgrade opensshUpgrade openssh-cavsUpgrade pam_ssh_agent_authUpgrade openssh-askpass | Aug 2, 2026 | Jul 29, 2026 |
| Amazon_linux_2023 | — | Upgrade openssh-debuginfoUpgrade opensshUpgrade openssh-serverUpgrade openssh-keycat-debuginfoUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh-clientsUpgrade pam_ssh_agent_authUpgrade openssh-keycatUpgrade openssh-sk-dummy-debuginfoUpgrade openssh-clients-debuginfoUpgrade openssh-sk-dummyUpgrade openssh-debugsourceUpgrade openssh-server-debuginfo | Aug 10, 2026 | Jun 23, 2026 |
| Redhat_linux | — | Upgrade openssh-serverUpgrade openssh-sk-dummy-debuginfoUpgrade openssh-debugsourceUpgrade pam_ssh_agent_authUpgrade openssh-server-debuginfoNo solution existsUpgrade openssh-cavs-debuginfoUpgrade openssh-keysign-debuginfoUpgrade openssh-clients-debuginfoUpgrade openssh-debuginfoUpgrade openssh-keycat-debuginfoUpgrade openssh-ldap-debuginfoUpgrade openssh-cavsUpgrade openssh-keysignUpgrade openssh-keycatUpgrade openssh-askpass-debuginfoUpgrade openssh-clientsUpgrade opensshUpgrade openssh-ldapUpgrade openssh-askpassUpgrade pam_ssh_agent_auth-debuginfo | Jul 17, 2026 | Jun 22, 2026 |
| Rocky_linux | — | Upgrade openssh-keycatUpgrade openssh-askpassUpgrade pam_ssh_agent_authUpgrade openssh-clients-debuginfoUpgrade openssh-clientsUpgrade openssh-server-debuginfoUpgrade openssh-debuginfoUpgrade openssh-serverUpgrade openssh-debugsourceUpgrade openssh-ldap-debuginfoUpgrade openssh-keycat-debuginfoUpgrade openssh-cavs-debuginfoUpgrade openssh-askpass-debuginfoUpgrade openssh-ldapUpgrade openssh-cavsUpgrade pam_ssh_agent_auth-debuginfoUpgrade openssh | Aug 3, 2026 | Jul 30, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Aug 3, 2026 | Jun 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub