{"id":"UBUNTU-CVE-2026-55655","details":"A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.","modified":"2026-09-11T20:50:33.370699307Z","published":"2026-06-23T04:17:00Z","upstream":["CVE-2026-55655"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-55655"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-55655"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-55655"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2462250"}],"affected":[{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-8","1:7.5p1-9","1:7.5p1-9build1","1:7.5p1-10"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client-ssh1","binary_version":"1:7.5p1-10"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55655.json"}},{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-11build1"],"ecosystem_specific":{"binaries":[{"binary_version":"1:7.5p1-11build1","binary_name":"openssh-client-ssh1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55655.json"}},{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-12","1:7.5p1-12build1","1:7.5p1-13"],"ecosystem_specific":{"binaries":[{"binary_version":"1:7.5p1-13","binary_name":"openssh-client-ssh1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55655.json"}},{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-14","1:7.5p1-15","1:7.5p1-15build1","1:7.5p1-16"],"ecosystem_specific":{"binaries":[{"binary_version":"1:7.5p1-16","binary_name":"openssh-client-ssh1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55655.json"}},{"package":{"name":"openssh","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/openssh?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:9.9p1-3ubuntu3","1:9.9p1-3ubuntu3.1","1:10.0p1-5ubuntu2","1:10.0p1-5ubuntu3","1:10.0p1-5ubuntu4","1:10.0p1-5ubuntu5","1:10.0p1-5ubuntu5.1","1:10.0p1-5ubuntu5.4"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client","binary_version":"1:10.0p1-5ubuntu5.4"},{"binary_name":"openssh-client-gssapi","binary_version":"1:10.0p1-5ubuntu5.4"},{"binary_name":"openssh-server","binary_version":"1:10.0p1-5ubuntu5.4"},{"binary_name":"openssh-server-gssapi","binary_version":"1:10.0p1-5ubuntu5.4"},{"binary_name":"openssh-sftp-server","binary_version":"1:10.0p1-5ubuntu5.4"},{"binary_name":"openssh-tests","binary_version":"1:10.0p1-5ubuntu5.4"},{"binary_version":"1:10.0p1-5ubuntu5.4","binary_name":"ssh"},{"binary_version":"1:10.0p1-5ubuntu5.4","binary_name":"ssh-askpass-gnome"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55655.json"}},{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-17"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client-ssh1","binary_version":"1:7.5p1-17"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55655.json"}},{"package":{"name":"openssh-ssh1","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/openssh-ssh1?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1:7.5p1-17","1:7.5p1-18"],"ecosystem_specific":{"binaries":[{"binary_name":"openssh-client-ssh1","binary_version":"1:7.5p1-18"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-55655.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"},{"type":"Ubuntu","score":"medium"}]}