#1143936 openssh: CVE-2026-55655

Package:
src:openssh
Source:
src:openssh
Submitter:
Moritz Mühlenhoff
Date:
2026-08-08 16:31:01 UTC
Severity:
normal
Tags:
#1143936#5
Date:
2026-08-08 16:29:27 UTC
From:
To:
Hi,

The following vulnerability was published for openssh.

CVE-2026-55655[0]:
| A flaw was found in OpenSSH. A local unprivileged attacker on a
| Linux client host can hijack client-side X11 forwarding connections.
| This is possible by pre-binding the preferred abstract X socket name
| when X11 forwarding is enabled and a local UNIX-domain X socket is
| used. A successful attack can compromise the confidentiality of
| forwarded X11 traffic, including sensitive window contents and
| input, and may allow some manipulation of the forwarded session.

https://bugzilla.redhat.com/show_bug.cgi?id=2462250 is the only
reference and Red Hat released an update, but it's unclear whether
this is an issue in upstream OpenSSH or one of their patches.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-55655
https://www.cve.org/CVERecord?id=CVE-2026-55655

Please adjust the affected versions in the BTS as needed.