Protection mechanism failure in OpenSSH - CVE-2025-32728
Published: April 10, 2025 / Updated: April 24, 2025
Vulnerability details
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to software does not properly handle the DisableForwarding directive, which does not disable X11 forwarding and agent forwarding as documented. A remote user can bypass expected application's behavior and bypass implemented security restrictions.
Affected software
Oracle Communications Session Border Controller
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
OpenBSD
Basesystem Module
Desktop Applications Module
openSUSE Leap
openEuler
Ubuntu
Fedora
Oracle Solaris
Oracle Enterprise Communications Broker
Traffix SDC
LANTIME Operating System Firmware (LTOS)
pam_ssh_agent_auth
openssh-client (Ubuntu package)
openssh-server (Ubuntu package)
openssh-askpass
openssh-help
openssh-server
openssh-ldap
openssh-keycat
openssh-debugsource
openssh-debuginfo
openssh-clients
openssh-cavs
openssh
openssh-common
openssh-clients-debuginfo
openssh-askpass-gnome-debuginfo
openssh-server-debuginfo
openssh-helpers
openssh-askpass-gnome-debugsource
openssh-askpass-gnome
openssh-common-debuginfo
openssh-cavs-debuginfo
openssh-fips
openssh-helpers-debuginfo
openssh-server-config-disallow-rootlogin
How to mitigate CVE-2025-32728
LANTIME Operating System Firmware (LTOS) - update to 7.08.024
pam_ssh_agent_auth - addressed in versions 0.10.3-9.31, 0.10.4-4.6, 0.10.4-4.8, 0.10.4-4.35
openssh-client (Ubuntu package) - addressed in versions 1:8.2p1-4ubuntu0.13, 1:8.9p1-3ubuntu0.13, 1:9.6p1-3ubuntu13.11, 1:9.7p1-7ubuntu4.3, 1:9.9p1-3ubuntu3.1
openssh-server (Ubuntu package) - addressed in versions 1:8.2p1-4ubuntu0.13, 1:8.9p1-3ubuntu0.13, 1:9.6p1-3ubuntu13.11, 1:9.7p1-7ubuntu4.3, 1:9.9p1-3ubuntu3.1
openssh-askpass - addressed in versions 8.2p1-31, 8.8p1-35, 9.3p2-8, 9.6p1-6
openssh-help - addressed in versions 8.2p1-31, 8.8p1-35, 9.3p2-8, 9.6p1-6
openssh-server - addressed in versions 8.2p1-31, 8.8p1-35, 9.3p2-8, 9.6p1-6
openssh-ldap - update to 8.2p1-31
openssh-keycat - addressed in versions 8.2p1-31, 8.8p1-35, 9.3p2-8, 9.6p1-6
openssh-debugsource - addressed in versions 8.2p1-31, 8.8p1-35, 9.3p2-8, 9.6p1-6
openssh-debuginfo - addressed in versions 8.2p1-31, 8.8p1-35, 9.3p2-8, 9.6p1-6
openssh-clients - addressed in versions 8.2p1-31, 8.8p1-35, 9.3p2-8, 9.6p1-6
openssh-cavs - update to 8.2p1-31
openssh - addressed in versions 8.2p1-31, 8.8p1-35, 9.3p2-8, 9.6p1-6
openssh-common - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-clients-debuginfo - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-debuginfo - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-askpass-gnome-debuginfo - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-server-debuginfo - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-helpers - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-clients - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-askpass-gnome-debugsource - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-cavs - update to 8.4p1-150300.3.49.1
openssh-askpass-gnome - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-common-debuginfo - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-debugsource - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-cavs-debuginfo - update to 8.4p1-150300.3.49.1
openssh-fips - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-helpers-debuginfo - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-server - addressed in versions 8.4p1-150300.3.49.1, 9.6p1-150600.6.26.1
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.26.1
openssh - addressed in versions 9.9p1-4.fc41, 9.9p1-11.fc42
Oracle Solaris - addressed in versions 11.3 ESU 36.35, 11.4 SRU 89
External References
Related Security Bulletins
- Security restrictions bypass in OpenSSH
- OpenBSD update for OpenSSH
- Ubuntu update for openssh
- openEuler 20.03 LTS SP4 update for openssh
- openEuler 24.03 LTS update for openssh
- Fedora 41 update for openssh
- Fedora 42 update for openssh
- SUSE update for openssh
- openEuler 22.03 LTS SP4 update for openssh
- SUSE update for openssh
- Meinberg LANTIME firmware update for third-party components
- openEuler 24.03 LTS SP1 update for openssh
- openEuler 22.03 LTS SP3 update for openssh
- Security restrictions bypass in Traffix SDC OpenSSH component
- Multiple vulnerabilities in Oracle Communications Session Border Controller
- Multiple vulnerabilities in Oracle Enterprise Communications Broker
- Multiple vulnerabilities in Oracle Solaris