CVE-2025-32728
Published: April 11, 2025Last modified: August 1, 2025
Description
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 3.8 |
| Attack Vector | LOCAL |
| Attack complexity | LOW |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | CHANGED |
| Confidentiality | NONE |
| Integrity impact | LOW |
| Availability impact | NONE |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | openssh | Fixed (9.1_p1-r10) |
| Stream | openssh | Fixed (10.0_p1-r1) | |
| Hardened Containers | 23 LTS | openssh | Fixed (9.1_p1-r10) |
| Stream | openssh | Fixed (10.0_p1-r1) |
References
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/013_ssh.patch.sig
- https://github.com/openssh/openssh-portable/commit/fc86875e6acb36401dfc1dfb6b628a9d1460f367
- https://lists.debian.org/debian-lts-announce/2025/05/msg00008.html
- https://lists.mindrot.org/pipermail/openssh-unix-dev/2025-April/041879.html
- https://security.netapp.com/advisory/ntap-20250425-0002/
- https://www.openssh.com/txt/release-10.0
- https://www.openssh.com/txt/release-7.4