hn.today

OpenSSH 10.6 Released

openssh.org8 points1 comments
Screenshot of OpenSSH 10.6 Released

OpenSSH 10.6, released 2026-10-06, introduces a faster cadence of point releases in response to a surge of security bug reports (many originating from or assisted by AI) and thanks contributors. It begins deprecating scp's -R remote-to-remote execution, and warns that support for platforms lacking file-descriptor passing and requiring root for PTY allocation (notably QNX 6 and SCO OpenServer 5) will be removed; on those platforms GatewayPorts and StreamLocalForwarding are forcibly disabled. Command-line destination usernames are now more strictly validated (disallowing $ and \), and compression effectiveness will be reduced because of a security-related change described below.

Security and robustness fixes include stricter sftp path validation to prevent recursive-copy escape, ensuring GSSAPI credentials are only stored on successful auth and resetting GSSAPI state between attempts, and bounds-checking compressed payloads. The LZ77 dictionary coder is disabled to mitigate a compression side-channel (chosen-plaintext) attack that can recover secrets via a shared compression dictionary. New features include a hybrid post-quantum ssh-mldsa44-ed25519 signature algorithm (old experimental keys must be regenerated), a server-side WarnWeakCrypto option, preservation of FIDO resident-key user-verification via credProtect, ssh-keygen hexdump export, ssh-add -P, sftp -p, AgentSocketPath/ssh-agent -A for agent socket handling, PubkeyOptions max-pk-ok to reduce auth failures from excessive PK_OK checks, TCPKeepAlive enhancements, and multiple platform and internationalization bugfixes.

Read on openssh.org1 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.