Among the 26 debian patches available in version 1:10.2p1-5 of the package, we noticed the following issues:
commit 0e02cd7b4e863db0c0f3d158cf6abbb4bf5dac58
Merge: 2d7033ef 6818014c
Author: Colin Watson <cjwatson@debian.org>
Date: Thu Feb 19 15:17:15 2026 +0000
Merge branch 'deluser' into 'master'
Stop deleting system user on remove/purge
See merge request ssh-team/openssh!38
commit 6818014c9f35bda4040d4ced7c40feb2b2a9b744
Author: Luca Boccassi <luca.boccassi@gmail.com>
Date: Thu Feb 19 11:14:48 2026 +0000
Stop deleting system user on remove/purge
This is widely considered bad practice, as the kernel recycles
UIDs/GIDs. So any potential leftover file/directory can then
become owned by the next user/group that gets added, with
unpredictable consequences.
There are 2 open security issues in trixie.
You can find information about how to handle these issues in the security team's documentation.