First published: Thu Apr 24 2025(Updated: )
It was discovered that OpenSSH incorrectly handled the DisableForwarding directive. The directive would fail to disable X11 and agent forwarding, contrary to documentation and expectations.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/openssh-client | <1:9.9p1-3ubuntu3.1 | 1:9.9p1-3ubuntu3.1 |
Ubuntu | =25.04 | |
All of | ||
ubuntu/openssh-server | <1:9.9p1-3ubuntu3.1 | 1:9.9p1-3ubuntu3.1 |
Ubuntu | =25.04 | |
All of | ||
ubuntu/openssh-client | <1:9.7p1-7ubuntu4.3 | 1:9.7p1-7ubuntu4.3 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/openssh-server | <1:9.7p1-7ubuntu4.3 | 1:9.7p1-7ubuntu4.3 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/openssh-client | <1:9.6p1-3ubuntu13.11 | 1:9.6p1-3ubuntu13.11 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/openssh-server | <1:9.6p1-3ubuntu13.11 | 1:9.6p1-3ubuntu13.11 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/openssh-client | <1:8.9p1-3ubuntu0.13 | 1:8.9p1-3ubuntu0.13 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/openssh-server | <1:8.9p1-3ubuntu0.13 | 1:8.9p1-3ubuntu0.13 |
Ubuntu | =22.04 | |
All of | ||
ubuntu/openssh-client | <1:8.2p1-4ubuntu0.13 | 1:8.2p1-4ubuntu0.13 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/openssh-server | <1:8.2p1-4ubuntu0.13 | 1:8.2p1-4ubuntu0.13 |
Ubuntu | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-7457-1 is considered to be high due to the incorrect handling of the DisableForwarding directive in OpenSSH.
To fix USN-7457-1, upgrade your OpenSSH packages to the patched versions 1:9.9p1-3ubuntu3.1 or later.
USN-7457-1 affects OpenSSH client and server versions prior to 1:9.9p1-3ubuntu3.1 across various Ubuntu releases.
USN-7457-1 impacts Ubuntu systems running versions 25.04, 24.10, 24.04, 22.04, and 20.04 with vulnerable OpenSSH installations.
Yes, the vulnerability in USN-7457-1 can be exploited to enable unintended X11 and agent forwarding, posing a security risk.