{"id":"ECHO-6dfe-b27a-9111","summary":"Local MITM of client-side X11 forwarding via abstract UNIX socket\npre-binding, scoped by upstream to Red Hat Enterprise Linux OpenSSH\nclients. The vulnerable abstract-socket-first behavior is introduced\nby Red Hat's downstream openssh-7.2p2-x11.patch, which Debian does not\ncarry: in the Debian openssh sources connect_local_xsocket() only\nconnects to the filesystem-path X socket, and no debian/patches entry\ntouches this code, so the vulnerable code path is not present. Debian\nrates it undetermined.\n","modified":"2026-09-15T03:33:52.846298013Z","published":"2026-06-23T20:13:57.906Z","withdrawn":"2026-07-27T11:15:03.783Z","upstream":["CVE-2026-55655"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-55655"}],"affected":[{"package":{"name":"openssh","ecosystem":"Echo","purl":"pkg:deb/echo/openssh"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:10.4p1-1+e2"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-6dfe-b27a-9111.json"}}],"schema_version":"1.9.0"}