CVE-2025-32728
Published: April 11, 2025Last modified: August 1, 2025
Description
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.
Severity score breakdown
| Parameter | Value | 
|---|---|
| Base score | 3.8 | 
| Attack Vector | LOCAL | 
| Attack complexity | LOW | 
| Privileges required | LOW | 
| User interaction | NONE | 
| Scope | CHANGED | 
| Confidentiality | NONE | 
| Integrity impact | LOW | 
| Availability impact | NONE | 
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N | 
Status
| Product | Release | Package | Status | 
|---|---|---|---|
| Alpaquita Linux | 23 LTS | openssh | Fixed (9.1_p1-r10) | 
| Stream | openssh | Fixed (10.0_p1-r1) | |
| Hardened Containers | 23 LTS | openssh | Fixed (9.1_p1-r10) | 
| Stream | openssh | Fixed (10.0_p1-r1) | 
References
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/013_ssh.patch.sig
 - https://github.com/openssh/openssh-portable/commit/fc86875e6acb36401dfc1dfb6b628a9d1460f367
 - https://lists.debian.org/debian-lts-announce/2025/05/msg00008.html
 - https://lists.mindrot.org/pipermail/openssh-unix-dev/2025-April/041879.html
 - https://security.netapp.com/advisory/ntap-20250425-0002/
 - https://www.openssh.com/txt/release-10.0
 - https://www.openssh.com/txt/release-7.4