ECHO-6dfe-b27a-9111

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-6dfe-b27a-9111.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-6dfe-b27a-9111
Upstream
Withdrawn
2026-07-27T11:15:03Z
Published
2026-06-23T20:13:57Z
Modified
2026-09-15T03:33:52Z
Summary
Local MITM of client-side X11 forwarding via abstract UNIX socket pre-binding, scoped by upstream to Red Hat Enterprise Linux OpenSSH clients. The vulnerable abstract-socket-first behavior is introduced by Red Hat's downstream openssh-7.2p2-x11.patch, which Debian does not carry: in the Debian openssh sources connect_local_xsocket() only connects to the filesystem-path X socket, and no debian/patches entry touches this code, so the vulnerable code path is not present. Debian rates it undetermined.
Details
References

Affected packages

Echo / openssh

Package

Name
openssh
Purl
pkg:deb/echo/openssh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1:10.4p1-1+e2

Database specific

source
"https://advisory.echohq.com/osv/ECHO-6dfe-b27a-9111.json"