Fedora Account System
Red Hat Associate
Red Hat Customer
When I attempt to ssh into a fully updated Fedora Linux 44 system, I see this: $ ssh -X fedora-test X11 forwarding request failed on channel 1 fedora-test $ If I look at recent selinux AVCs, I see: $ sudo ausearch -m avc -ts recent time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:561): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6010 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:562): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6011 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:563): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6012 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:564): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6013 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:565): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6014 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:566): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6015 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:567): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6016 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:568): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6017 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:569): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6018 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:570): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6019 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:571): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6020 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:572): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6021 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:573): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6022 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:574): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6023 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:575): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6024 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:576): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6025 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:577): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6026 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- time->Wed Aug 26 10:36:26 2026 type=AVC msg=audit(1787754986.272:578): avc: denied { name_bind } for pid=3763 comm="sshd-session" src=6027 scontext=system_u:system_r:sshd_session_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket permissive=0 ---- (for thousands of AVCs) Just for example: $ sudo ausearch -m avc -ts recent | grep -c sshd_session_t 1857 Putting SELinux into permissive mode makes the issue go away. I believe this is due to the change to remove the sshd_session_t permissive domain (https://github.com/fedora-selinux/selinux-policy/commit/963c9ea0194da33f0058e8e6840ba484bb1c9aaa) Reproducible: Always Steps to Reproduce: 1. Have a remote Fedora 44 system with sshd running 2. run "ssh -X remotehost" Actual Results: X11 forwarding is not enabled Expected Results: X11 forwarding works Additional Information: I built a custom selinux-policy package which just reverts the removal of those permissive domains, and the ssh -X now works, which is a good indicator that the commit mentioned above introduced this behavior.
Created attachment 2155704 [details] Reverts the removal of the sshd_auth_t and sshd_session_t permissive domains
Related upstream issue: https://github.com/fedora-selinux/selinux-policy/issues/3384
FEDORA-2026-16b888c99f (selinux-policy-44.8-1.fc44) has been submitted as an update to Fedora 44. https://bodhi.fedoraproject.org/updates/FEDORA-2026-16b888c99f
FEDORA-2026-16b888c99f has been pushed to the Fedora 44 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-16b888c99f` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-16b888c99f See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-16b888c99f (selinux-policy-44.8-1.fc44) has been pushed to the Fedora 44 stable repository. If problem still persists, please make note of it in this bug report.