OpenSSH 10.6 Post-Quantum Signature: Replace Experimental Keys Now
OpenSSH 10.6 introduces post-quantum signature support and various security enhancements.
OpenSSH 10.6 Release Announcement
The OpenSSH development team announced the release of version 10.6 on October 6, citing an increased frequency of updates to expedite bug fixes. This shift follows a surge in security reports, many identified through AI-driven analysis or collaborative research efforts. The maintainers noted that independent researchers frequently validated similar vulnerabilities, warning that malicious actors could exploit unreported flaws. Users operating sshd or the ssh client should anticipate more frequent updates moving forward.
Security Vulnerabilities and Mitigations
Security researchers Fabian Bäumer and Marcus Brinkmann detailed a vulnerability where an attacker controlling one channel could extract secrets from another. The shared compression dictionary across all session channels allows repeated strings to alter ciphertext length, prompting recommendations for application-level compression which offers better performance and resistance to this specific attack vector.
Compression Functionality Changes
Compression functionality weakened in this release as both components disable the LZ77 dictionary coder, reducing the effectiveness of the Compression option.
Username Restrictions
Enhanced restrictions on username characters were implemented to prevent potential shell injection attacks. The ssh utility now blocks command-line usernames containing $ or \ symbols, as untrusted inputs could exploit ProxyCommand or Match exec directives. Config file-defined usernames via the User directive remain unaffected.
GSSAPI Credential Handling Improvements
The maintainers acknowledged that such mitigations cannot guarantee absolute security. Additional security improvements include modifications to how sshd handles GSSAPI credentials, which are now stored only after successful authentication. Previously, failed attempts could leave credentials exposed during subsequent successful sessions.
SFTP Path Validation Enhancements
The sftp component now enforces stricter validation of server-returned paths, preventing scenarios where a server might redirect recursive transfers outside designated directories.
Time-Related Bug Fix
A time-related bug in ssh-keygen caused certificate expiration times to deviate by up to an hour, or two hours in the Antarctica/Troll timezone, due to improper handling of Daylight Saving Time transitions.
Post-Quantum Signature Algorithm Integration
The update also incorporates the hybrid post-quantum signature algorithm ssh-mldsa44-ed25519. Users must regenerate or remove keys generated under previous experimental implementations to maintain compatibility and security.
Additional Security Notes
On QNX 6, SCO OpenServer 5, and systems built with disable-fd-passing, the post-authentication process retains root privileges, leading to the deactivation of GatewayPorts and StreamLocalForwarding features. These platforms may lose support if alternative solutions are not developed.
