OpenSSH 10.6 Disables LZ77 compression, Enables PQ signatures

OpenSSH 10.6 shipped on October 6, disabling part of its compression to close a side-channel attack and enabling a post-quantum signature algorithm by default. The release notes open with something more interesting than either.

The project says it has received a large number of security bug reports latelyMany of them conclusions from AI models or made with AI help. It welcomes them, especially when they are paired Human triage and suggested fixes.

Then the part that put it up with asterisks for emphasis: OpenSSH has seen cases where a bug found by AI tools was later discovered independently by another researcher. His conclusion is that adversaries who do not report bugs are likely to find them. So instead of batching fixes until the next scheduled release, the project will now ship more frequently.

That’s a maintenance team changing its release technique because the economics of bug discovery have changed. 10.6 comes about eight weeks after 10.5, which itself came five weeks after 10.4.

Two fixes in this release are credited to Chris Rohlf in collaboration with Claude and Anthropic Research. Check out – 8 Best SSH Clients for Windows 11

Change the compression

OpenSSH has the LZ77 dictionary encoder disabled in both client and server.

The attack it addresses is described in “Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels” by Fabian Bäumer and Marcus Brinkmann.

The mechanism is less obvious than most side channels. A single SSH connection can carry several channels at once, say an interactive shell and a port forward. Compression runs across all of them with a common search buffer. LZ77 works by replacing repeated strings with back-references to that buffer, so when an attacker checks the input on one channel to see if their text matches secret data on another channel, the length of the encrypted output changes. Look long enough, and the secret can be recovered.

Disabling dictionary encoding removes the common context leak. Compression still works but less effectively, which OpenSSH lists under potentially incompatible changes. Its recommendation is instead to compress at the application layer via SSH, which it says is usually more effective and completely immune to this class of attacks.

The documentation already advised against compression on connections that mix trusted and untrusted traffic. This makes the mitigation unconditional.

Post-quantum signatures go live

The hybrid ssh-mldsa44-ed25519 algorithm, experimental in 10.4, is now enabled.

One thing to note: the “@openssh.com” vendor suffix is ​​gone. Keys generated with the experimental implementation must be regenerated or deleted. If you tried this in July, these keys will not work.

Servers also gain WarnWeakCrypto and sshd_config, previously client-only. It is standardized and logged when a client negotiates a key contract scheme that is not post-quantum security. That gives administrators a way to find which clients still need upgrading before the harvest-now-decrypt-later concerns.

The other security fixes

  • Username injection. The ssh client now refuses $ and backslashes and usernames specified on the command line, close a shell injection path via ProxyCommand and Match Exec. Usernames from configuration files are exempt. Reported by SecBuddyF, KeenLab Tencent. OpenSSH reiterates its steadfast advice against exposing command lines to untrusted input at all.
  • SFTP path validation. Strict checking of server return paths, preventing a malicious server from performing a recursive copy and write outside the target directory. Report with a patch by Junghoon Cho.
  • Two GSSAPI fixes. Credentials from a failed GSSAPI attempt might persist and become available if a subsequent attempt succeeds. State could also carry between attempts.
  • A daylight saving bug and ssh-keygen date conversion could produce certificates with expiration times incorrect by up to one hour, or two hours in the Antarctic/Troll time zone.
  • Restrict keyword and authorized_keys was not applied to tunnel forwarding, a separate issue from the one fixed in 10.5.

On platforms that cannot pass file descriptors and require root for PTY allocation, including QNX 6 and SCO OpenServer 5, GatewayPorts and StreamLocalForwarding are now forcibly disabled, as the post-authentication process stops root there and could bypass user-level controls. Support for these platforms is scheduled to be removed.

macOS sandboxing is gone on SDK 27 and later, because the API OpenSSH has been trusted with no alternative offered.

Everything else

Standard KDF rounds for private keys increase from 24 to 32, a linear increase.

scp of -R Flag for remote-to-remote copies now emits a rejection warning and is ultimately ignored.

New conveniences included -p for sftp mkdir, a -P Flag for ssh-add to skip PIN entry on tokens that don’t need it, fractional-second ChannelTimeout values, configurable agent socket paths, and separate accounting for public key “key ok” probes so more keys can be offered before MaxAuthTries offers.

Leave a Comment