Upstream information
Description
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.SUSE information
Overall state of this security issue: Resolved
This issue is currently rated as having moderate severity.
| CVSS detail | CNA (Red Hat) | National Vulnerability Database |
|---|---|---|
| Base Score | 5 | 6.1 |
| Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N |
| Attack Vector | Local | Local |
| Attack Complexity | High | Low |
| Privileges Required | Low | None |
| User Interaction | Required | Required |
| Scope | Unchanged | Unchanged |
| Confidentiality Impact | High | High |
| Integrity Impact | Low | Low |
| Availability Impact | None | None |
| CVSSv3 Version | 3.1 | 3.1 |
SUSE Security Advisories:
- RHSA-2026:47755, published Fri Jul 31 15:06:56 UTC 2026
- RHSA-2026:47756, published Thu Jul 30 15:06:29 UTC 2026
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Liberty Linux 10 |
| Patchnames: RHSA-2026:47757 |
| SUSE Liberty Linux 8 |
| Patchnames: RHSA-2026:47755 |
| SUSE Liberty Linux 9 |
| Patchnames: RHSA-2026:47756 |
SUSE Timeline for this CVE
CVE page created: Wed Jul 29 21:52:57 2026CVE page last modified: Fri Jul 31 20:39:09 2026