CVE-2025-32728

NameCVE-2025-32728
DescriptionIn sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1102603

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
openssh (PTS)bullseye1:8.4p1-5+deb11u3vulnerable
bullseye (security)1:8.4p1-5+deb11u4vulnerable
bookworm, bookworm (security)1:9.2p1-2+deb12u5vulnerable
trixie1:9.9p2-2vulnerable
sid1:10.0p1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
opensshsource(unstable)1:10.0p1-11102603

Notes

[bookworm] - openssh <no-dsa> (Minor issue)
[bullseye] - openssh <postponed> (Minor issue, local X11/agent forwarding disabled by default in the client)
https://lists.mindrot.org/pipermail/openssh-unix-dev/2025-April/041879.html
Fixed by: https://github.com/openssh/openssh-portable/commit/fc86875e6acb36401dfc1dfb6b628a9d1460f367 (V_10_0_P1)

Search for package or bug name: Reporting problems