Executive brief
A security flaw in OpenSSH allows a local attacker on a Linux computer to intercept and view graphical data from an SSH session that has X11 forwarding enabled. By tricking the system into connecting to a malicious socket, the attacker can capture sensitive information like window contents, keystrokes, and login credentials used within the forwarded graphical applications. This requires the attacker to already have a local account on the same machine where the SSH client is being used.
Technical details
A vulnerability exists in the OpenSSH client's X11 forwarding logic on Linux systems. When X11 forwarding is enabled and the DISPLAY environment variable points to a local UNIX-domain socket (e.g., :0), the client attempts to connect to an abstract UNIX socket before the filesystem-based socket. Because Linux abstract sockets do not have filesystem permission protections, a local unprivileged attacker can pre-bind the preferred abstract socket name (\0/tmp/.X11-unix/X<display>). When a forwarded X11 connection is initiated, the OpenSSH client connects to the attacker's socket, allowing the attacker to intercept sensitive X11 traffic, including authentication data and window contents. This issue affects OpenSSH versions on Linux that prioritize abstract sockets in connect_local_xsocket().
Affected products
- OpenSSH OpenSSH 9.9p1-22.el10_2 and potentially others on Linux
- Red Hat Red Hat Enterprise Linux 10 openssh-9.9p1-22.el10_2
- Red Hat Red Hat Enterprise Linux 6 openssh
- Red Hat Red Hat Enterprise Linux 7 openssh
- Red Hat Red Hat Enterprise Linux 8 openssh
- Red Hat Red Hat Enterprise Linux 9 openssh
Timeline
- 2026-04-26: disclosed: Reported via Red Hat Bugzilla
- 2026-06-23: advisory: NVD and Red Hat published advisory details