RHSA-2025:20126MediumCVSS 4.3

Red Hat Security Advisory: openssh security update

Published
November 11, 2025
Last Modified
September 1, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2025-32728 — openssh: OpenSSH SSHD Agent Forwarding and X11 Forwarding

🎯 Affected products91

  • Red Hat Enterprise Linux AppStream (v. 10)
  • Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-0:9.9p1-11.el10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-0:9.9p1-11.el10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-0:9.9p1-11.el10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-0:9.9p1-11.el10.src as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-0:9.9p1-11.el10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-askpass-0:9.9p1-11.el10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssh-askpass-0:9.9p1-11.el10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssh-askpass-0:9.9p1-11.el10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssh-askpass-0:9.9p1-11.el10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssh-askpass-debuginfo-0:9.9p1-11.el10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssh-askpass-debuginfo-0:9.9p1-11.el10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-askpass-debuginfo-0:9.9p1-11.el10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssh-askpass-debuginfo-0:9.9p1-11.el10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-askpass-debuginfo-0:9.9p1-11.el10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssh-askpass-debuginfo-0:9.9p1-11.el10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-askpass-debuginfo-0:9.9p1-11.el10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssh-askpass-debuginfo-0:9.9p1-11.el10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-clients-0:9.9p1-11.el10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-clients-0:9.9p1-11.el10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-clients-0:9.9p1-11.el10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-clients-0:9.9p1-11.el10.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-clients-debuginfo-0:9.9p1-11.el10.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssh-clients-debuginfo-0:9.9p1-11.el10.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-clients-debuginfo-0:9.9p1-11.el10.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssh-clients-debuginfo-0:9.9p1-11.el10.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-clients-debuginfo-0:9.9p1-11.el10.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssh-clients-debuginfo-0:9.9p1-11.el10.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssh-clients-debuginfo-0:9.9p1-11.el10.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • +61 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this vulnerability, explicitly disable X11 and agent forwarding in your SSH configuration (sshd_config) using: X11Forwarding no AllowAgentForwarding no

🔗 References (10)