Published release of OpenSSH 10.6, an open client and server implementation for running SSH 2.0 and SFTP protocols. Security issues have been fixed, most of which were identified when analyzing code using AI tools (CVE identifiers are not assigned):
- A vulnerability in sftp that allows a file to be written outside the target directory when accessing a server controlled by attackers.
- Two vulnerabilities in the GSSAPI implementation in sshd, caused by saving state between different authentication attempts. GSSAPI credentials could be stored after a failed authentication attempt and used after a subsequent successful authentication attempt.
Problems appear when the GSSAPIAuthentication setting is enabled. - Support for LZ77 compression is disabled in sshd and ssh due to the possibility of a side-channel attack allowing to recover content from another session when connecting through a common multiplexed connection with the victim, taking advantage of the fact that the attacker-controlled input data affects the total length of the transmitted encrypted messages (LZ77 replaces repeated lines with links in a buffer common to all channels).
- In the ssh utility, it is forbidden to use the characters ‘$’ and ” in user names entered on the command line, so they could be used to organize code execution when substituting names in the ProxyCommand and Match exec directives specified in the settings.
- In ssh-keygen, incorrect handling of daylight saving time was fixed, which led to to shift the validity period of certificates by 1 hour.
- To block the creation of zip bombs in sshd and ssh, a check has been added for exceeding the maximum packet size when unpacking data.
- In sshd, an issue has been resolved that allowed the restrictions of the “restrict” keyword in the authorized_keys file to be bypassed, which was not applied to tunnels (PermitTunnel).
- In sshd, the issue has been resolved. incorrect parsing of the “none” option inside Match blocks, which in some directives, such as AuthorizedPrincipalsFile, was interpreted as a file name rather than as a sign that the directive was disabled.
- Sshd fixes the lack of resetting root privileges on platforms that do not support transferring file descriptors and require root privileges to allocate PTYs. The problem appears in QNX 6, SCO OpenServer 5 and when building with the “–disable-fd-passing” option.
Non-vulnerability changes:
- Enabled support for hybrid crypto algorithm ssh-mldsa44-ed25519, which is resistant to brute force on quantum computers.
- In sshd_config, the WarnWeakCrypto option is implemented and enabled by default to control the output of connection warnings using key agreement algorithms that are not resistant to brute force on quantum computers.
- In ssh-keygen and ssh-add, credProtect policy checking is implemented in credentials to satisfy verification requirements (PIN or biometrics) before accessing resident keys on FIDO tokens.
- Added a “-P” flag to ssh-add to skip the optional PIN entry for FIDO tokens and PKCS#11.
/Reports, release notes, official announcements.