CVE-2026-55655

EUVD-2026-38413
A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 0.52%
Affected Products (NVD)
VendorProductVersion
openbsdopenssh
-
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
openssh
bookworm
undetermined
bookworm (security)
undetermined
bullseye
undetermined
bullseye (security)
undetermined
forky
undetermined
sid
undetermined
trixie
undetermined
trixie (security)
undetermined
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
openssh
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
questing
ignored
resolute
deferred
trusty
deferred
xenial
deferred
openssh-ssh1
bionic
ignored
focal
ignored
jammy
ignored
noble
ignored
questing
ignored
resolute
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
openssh
RHEL 8
0:8.0p1-30.el8_10
fixed
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-askpass
RHEL 8
0:8.0p1-30.el8_10
fixed
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-cavs
RHEL 8
0:8.0p1-30.el8_10
fixed
openssh-clients
RHEL 8
0:8.0p1-30.el8_10
fixed
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-keycat
RHEL 8
0:8.0p1-30.el8_10
fixed
RHEL 9
0:9.9p1-9.el9_8
fixed
openssh-ldap
RHEL 8
0:8.0p1-30.el8_10
fixed
openssh-server
RHEL 8
0:8.0p1-30.el8_10
fixed
RHEL 9
0:9.9p1-9.el9_8
fixed
pam
RHEL 8
0:0.10.3-7.30.el8_10
fixed
RHEL 9
0:0.10.4-7.9.el9_8
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
openssh
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-clients
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-clients-debuginfo
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-debuginfo
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-debugsource
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-keycat
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-keycat-debuginfo
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-server
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-server-debuginfo
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-sk-dummy
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
openssh-sk-dummy-debuginfo
Amazon Linux 2023
0:9.9p1-10.amzn2023.0.1
fixed
pam_ssh_agent_auth
Amazon Linux 2023
0:0.10.4-9.10.amzn2023.0.1
fixed
pam_ssh_agent_auth-debuginfo
Amazon Linux 2023
0:0.10.4-9.10.amzn2023.0.1
fixed