Bug 2524485 - SELinux prevents ssh X11 Forwarding due to removal of permissive sshd_session_t domain
Summary: SELinux prevents ssh X11 Forwarding due to removal of permissive sshd_session...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 44
Hardware: Unspecified
OS: Linux
unspecified
high
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-26 14:59 UTC by Jonathan Billings
Modified: 2026-08-31 17:18 UTC (History)
8 users (show)

Fixed In Version: selinux-policy-44.8-1.fc44
Clone Of:
Environment:
Last Closed: 2026-08-31 17:18:57 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
Reverts the removal of the sshd_auth_t and sshd_session_t permissive domains (1.17 KB, patch)
2026-08-26 15:02 UTC, Jonathan Billings
no flags Details | Diff

Description Jonathan Billings 2026-08-26 14:59:50 UTC
When I attempt to ssh into a fully updated Fedora Linux 44 system, I see this:

$ ssh -X fedora-test
X11 forwarding request failed on channel 1
fedora-test $

If I look at recent selinux AVCs, I see:

$ sudo ausearch -m avc -ts recent
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:561): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6010 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:562): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6011 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:563): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6012 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:564): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6013 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:565): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6014 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:566): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6015 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:567): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6016 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:568): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6017 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:569): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6018 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:570): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6019 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:571): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6020 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:572): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6021 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:573): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6022 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:574): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6023 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:575): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6024 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:576): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6025 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:577): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6026 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
time->Wed Aug 26 10:36:26 2026
type=AVC msg=audit(1787754986.272:578): avc:  denied  { name_bind } for  pid=3763 comm="sshd-session" src=6027 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0
----
(for thousands of AVCs)

Just for example:
$ sudo ausearch -m avc -ts recent | grep -c sshd_session_t
1857

Putting SELinux into permissive mode makes the issue go away.

I believe this is due to the change to remove the sshd_session_t permissive domain (https://github.com/fedora-selinux/selinux-policy/commit/963c9ea0194da33f0058e8e6840ba484bb1c9aaa)

Reproducible: Always

Steps to Reproduce:
1. Have a remote Fedora 44 system with sshd running
2. run "ssh -X remotehost"

Actual Results:
X11 forwarding is not enabled

Expected Results:
X11 forwarding works

Additional Information:
I built a custom selinux-policy package which just reverts the removal of those permissive domains, and the ssh -X now works, which is a good indicator that the commit mentioned above introduced this behavior.

Comment 1 Jonathan Billings 2026-08-26 15:02:27 UTC
Created attachment 2155704 [details]
Reverts the removal of the sshd_auth_t and sshd_session_t permissive domains

Comment 2 Jonathan Billings 2026-08-26 15:08:18 UTC
Related upstream issue:  https://github.com/fedora-selinux/selinux-policy/issues/3384

Comment 3 Fedora Update System 2026-08-27 21:53:34 UTC
FEDORA-2026-16b888c99f (selinux-policy-44.8-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-16b888c99f

Comment 4 Fedora Update System 2026-08-28 02:01:12 UTC
FEDORA-2026-16b888c99f has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-16b888c99f`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-16b888c99f

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 5 Fedora Update System 2026-08-31 17:18:57 UTC
FEDORA-2026-16b888c99f (selinux-policy-44.8-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.