-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 06 Oct 2026 18:00:40 +0100 Source: openssh Architecture: source Version: 1:10.6p1-1 Distribution: unstable Urgency: medium Maintainer: Debian OpenSSH Maintainers <debian-ssh@lists.debian.org> Changed-By: Colin Watson <cjwatson@debian.org> Closes: 1142934 1148080 Changes: openssh (1:10.6p1-1) unstable; urgency=medium . * New upstream release: - scp(1): begin deprecating the -R flag, which is used to perform a remote-to-remote copy by executing scp on a remote host. This option is a fragile optimisation that is difficult to use because it requires credentials on the remote host. It also creates security risks if the shell quoting rules on the remote system where the copy is performed differ from the client's expectations. . From OpenSSH 10.6, this option will continue to work but will cause a deprecation warning to be emitted to standard error. In a future release, the option will be ignored and will leave in place the default remote-to-remote copy behaviour (copy via the host running scp). - SECURITY: sftp(1): more strictly validate paths returned from the server to avoid some cases where a server could return paths that could manipulate a recursive copy operation into writing outside its target directory. - SECURITY: sshd(8): when GSSAPIAuthentication is in use, only store GSSAPI credentials when authentication has succeeded. Avoids a situation where credentials from a failed GSSAPIAuthentication attempt may persist and be made inappropriately available if another authentication subsequently succeeds. - SECURITY: sshd(8): reset GSSAPIAuthentication before authentication, avoiding state from one authentication attempt being confused with that of a later attempt. - SECURITY: sshd(8), ssh(1): disable LZ77 dictionary coder to mitigate side-channel leaks. A chosen-plaintext attack method exists which makes use of dictionary-based compression to recover secrets from one channel by interacting with the SSH session's shared compression dictionary through another channel. . Attacker-controlled input can recognizably reflect into the total length of transmitted ciphertexts by virtue of LZ77 replacing repeated strings with back-references into the SSH session's encoder search buffer, which is shared across all channels. For this reason, the documentation already recommended against enabling compression for connections that share trusted and untrusted traffic. . This change will reduce the effectiveness of the Compression option. Users are encouraged to use application-level compression over the SSH protocol where possible, as this will typically be more effective and will be completely immune to this type of attack. - SECURITY: ssh(1): disallow '$' and '\' characters in usernames entered on the command-line to avoid usernames from untrusted sources yielding injection in shell context via ProxyCommand, Match exec, etc. Usernames specified via the configuration files are not subject to this control. . We continue to recommend against directly exposing ssh(1) and other tools' command-lines to untrusted input. Mitigations such as this cannot be absolute given the variety of shells and user configurations in use. - SECURITY: ssh-keygen(1): correct handling of Daylight Saving Time when converting dates. Previous handling could cause errors of up to +/- 1 hour (unless you are in the Antarctica/Troll timezone, where the error could be +/- 2 hours). These errors could result in creation of certificates with incorrect expiry times. - SECURITY: sshd(8), ssh(1): ensure that compressed payloads don't inflate past the maximum supported packet length. - SECURITY: sshd(8): fully honor the authorized_keys "restrict" keyword, which was not being properly applied to tunnel forwarding (PermitTunnel, disabled by default). - SECURITY: sshd(8): correctly handle some options that accept "none". Some options, including AuthorizedPrincipalsFile, were documented as accepting "none" as a way to disable them; however, when overridden by an sshd_config(5) Match keyword, this argument was being incorrectly interpreted as a literal file. - All: enable hybrid post-quantum ssh-mldsa44-ed25519 signature algorithm. Note that this no longer uses the "@openssh.com" vendor extension suffix that the previous experimental implementation used. Keys generated with the previous experimental support must be regenerated and/or removed. - sshd(8): Add the WarnWeakCrypto option to sshd_config(5). This option was previously available for the client only. This option is enabled by default and will log when the client uses a key agreement scheme that is not post-quantum safe. - ssh-keygen(1), ssh-add(1): preserve user-verification (PIN or biometric) requirement for resident keys loaded from a FIDO token, by checking the credential's credProtect policy. - ssh(1): include local and remote version strings in the ~I connection information display. - ssh-add(1): add a -P flag to skip PIN entry for FIDO and PKCS#11 tokens that do not require it. - sftp(1): add '-p' flag for mkdir/lmkdir to create directories as required. This flag has similar ergonomics to mkdir(1), and previously-existing directories do not cause an error. - ssh-keygen(1): add a "hexdump" key export mode that dumps the SSH wire-formatted key blob in hex format. Useful when writing documentation, tests, etc. E.g. `ssh-keygen -em hexdump -f /key`. - ssh(1), sshd(8): ChannelTimeout now accepts timeouts with fractional seconds. - sshd(8): allow specification of the location of $SSH_AUTH_SOCK used for agent forwarding using a new AgentSocketPath option. This supports both using a user-specific path, such as the default of a subdirectory of $HOME ("user:.ssh/agent"), and the previous approach of allowing agent forwarding sockets to be located in a shared directory (e.g. "shared:/tmp"). Sockets created in shared directories will be created inside a subdirectory with a randomised name. - ssh-agent(1): allow specification of agent socket directories using a -A flag. It accepts "user:" and "shared:" directory styles similar to the sshd AgentSocketPath option. - sshd(8): account for public key authentication "key ok" tests separately to auth attempts. Add a `PubkeyOptions max-pk-ok:nnnn` option to allow a number of PK_OK tests (asking whether the server might accept a given public key) that do not count against MaxAuthTries, defaulting to 6 attempts. After these attempts are exhausted, further attempts count as failed authentications against MaxAuthTries. Practically, this allows more keys on disk or held in ssh-agent to be checked for use before the server disconnects. - ssh(1), sshd(8): extend the existing TCPKeepAlive option to also support setting keepalives on sockets created for forwarding connections. Previously this option controlled keepalives on the connection socket only. TCPKeepAlive "yes" or "transport" enables keepalives on the connection socket. "TCPKeepAlive all" additionally enables them for forwarding sockets. - sshd(8), ssh(1): fix configuration matching on more Turkic languages which have disjoint dotted and dotless i/I characters, specifically Azerbaijani and Crimean Tatar. - ssh(1), sshd(8): don't attempt to set TCP_NODELAY on non-IP/IPv6 sockets. Eliminates some noise in debug logs. - ssh(1): fix case for ssh -G option output. - ssh(1), sshd(8): Fix ChannelTimeout specificity; previously a more specific channel type (e.g. "session:shell") could clobber a user-specified ChannelTimeout if it was less specific (e.g. "session"). Also, in some cases, the debug messages were printing 0 instead of the effective timeout. - sftp(1): avoid NULL dereference crash in some circumstances when a server fails a stat/lstat operation. - sshd(8): close a race condition where a SIGTERM/SIGQUIT would be ignored if it was received by the server while it was processing a SIGHUP restart request. - sshd(8), ssh(1): check key and CA signature types during key parsing against allowlists (PubkeyAcceptedAlgorithms, etc) as early as possible. This reduces the attack surface presented by disabled algorithms. - All: switch the fallback implementation of the ed25519 signature algorithm used when libcrypto is disabled from SUPERCOP ed25519 to libsodium. The libsodium implementation includes a number of strictness checks over the original reference implementation we have used to this point and a more ergonomic API. - ssh-add(1), ssh(1), ssh-keygen(1): fix spin on password entry when the program attempting to read a password was started in a background process group, with no TTY and with certain signals ignored. - scp(1): disallow nul byte in received scp -O filename. This was not reachable in normal operation. - ssh-keygen(1), ssh(1), sshd(8): implement a maximum number of KDF rounds that will be accepted when writing an OpenSSH-format private key or when loading one. This limit is set quite high (1M), but ensures that a service that is passed a bad key with a ridiculously high number of rounds will eventually complete parsing it. - ssh-keygen(1): bump the default number of KDF rounds from 24 to 32 (this is a linear increase, not like bcrypt(3) which is exponential). - ssh(1): make StreamLocalBindMask properly respect Host/Match blocks and make it first-match-wins as documented. - sshd(8): make StreamLocalBindMask properly first-match-wins. - sshd(8): don't link sshd against libselinux when SELinux support is enabled (note: this library is still linked for the sshd-auth and sshd-session helper binaries). - sshd(8): restrict mremap(2) flags accepted by the seccomp sandbox. Only MREMAP_MAYMOVE is now accepted as other flags may have some utility in attack chains. - sshd(8): allow PAMServiceName in Match (regressed in 10.4). During the refactor of server option parsing, the ability to set PAMServiceName in Match blocks was accidentally disabled. * Generate MLDSA44-ED25519 host key by default (closes: #1142934). * Remove Lintian overrides that now only apply to openssh-gssapi. * Remove copyright entry that now only applies to openssh-gssapi. * Skip purging if openssh-{client,server}-gssapi is installed (closes: #1148080). Checksums-Sha1: ee742c720d4f07f88c6dee5577d75fc03b974303 3372 openssh_10.6p1-1.dsc 727535880c3bc75aabebe8e04c61eb92e9ae87a9 1653192 openssh_10.6p1.orig.tar.xz 1e1007ae4aa1a0333161387a89a885c309e37421 189064 openssh_10.6p1-1.debian.tar.xz 819445b12c8971f578ad94318c6e536897da4517 5589440 openssh_10.6p1-1.git.tar.xz 5b949e06224b49b05aa1058a3cd458216312f629 17730 openssh_10.6p1-1_source.buildinfo Checksums-Sha256: 3169605230f88ceeeffe12995c18bec6019d0649125326eea442dd76a19015d4 3372 openssh_10.6p1-1.dsc ff8514b95a2c4c8bafe07a87ac93d51bcf47bbe29ccbc185f2f9a9f86fd46c86 1653192 openssh_10.6p1.orig.tar.xz a12ee48c4a26c10473e7b781ce6c2df2228b648e3961fef051374407b50701a1 189064 openssh_10.6p1-1.debian.tar.xz 2df9b35db6a80cfea29c27efb42508f77d8517e5b1338bd9cd34870d8459d36c 5589440 openssh_10.6p1-1.git.tar.xz 41a617ab2e3d94ae3e701a45a0762f2916fe6b75bcc05cbd32330cd392049500 17730 openssh_10.6p1-1_source.buildinfo Files: 4d7febe26b02a5988341e4d4cab7eaa3 3372 net standard openssh_10.6p1-1.dsc 7e9bc157bf33ffead0f78861ba54faad 1653192 net standard openssh_10.6p1.orig.tar.xz 8118378fbd8d34cc8fb6f39cb2880519 189064 net standard openssh_10.6p1-1.debian.tar.xz 5840333c762bddca87fcfdc7b6348dbd 5589440 net standard openssh_10.6p1-1.git.tar.xz 8f16ee8c7cdc711c56f575914813f0fb 17730 net standard openssh_10.6p1-1_source.buildinfo Git-Tag-Info: tag=7b582bbe84635fbc51e2197b451e5a1b95f5d4c2 fp=ac0a4ff12611b6fccf01c111393587d97d86500b Git-Tag-Tagger: Colin Watson <cjwatson@debian.org> -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmrFKgMACgkQYG0ITkaD wHkq1RAA3CCTQX/cytAOurZ8oiDkn3HwPkFvygviWfkn/qWUMgaQPdicOl4C7i+K 3QbP38DGS5J9V+cUoCMSo1h9S3LgaeVggzohJasv7CtayB4csr1JsY7nzquQ6gxH QdLmCK2CnUYPuH/ryle9k49lfKcZEbMWSSzipWEMpl+MxJHiPNe58NY4q7E2Y3m4 Oygii8RGZ4cgDUf+KyQbQBvao2It8EMQWsXIItWSsDaLy5XLcCulWBG44adIQifq j51ISD5Xojn9vXtR3ZdphoagXrqlHPbXeYOkonBG1w9HZy2myP5Zy9HdmSC/LbGN +XXdg80u5PzPyrW6FsAvauSSJ4K84vNxNrkLl4jC/dRjHw5AMLWd5T/EJ6HEYZt3 2FTuw0+mYzuO3kAB3c3LYlYXYIL2OYUy3SE20X+/1uS9tse7y0HL/vb2AjIyx9XG iaEHulRAyHftnRyJaXjO6XcwwZiKTx7pbSoenSQ5L2P6xX5H/Id7e8foAhxQHFN/ rBx3wfr9mqIcy1tD5BZpTCXe01waA7xuAtneB3XX2pEwyqYJvy3XmiCBP04veEnd YJoSn15e3IIIZ+imrRPQIX7ygU7s6EcWz02xfIOuDLCou8A2INvLOurn5gn3H1c4 ZmThkuaf4RTcKkgYFyppBCuKdXpibW4QOHr++n21lfynEDUQ6oA= =wfYU -----END PGP SIGNATURE-----