The OpenSSH project released version 10.6 on October 6, introducing a new hybrid post-quantum signature algorithm and addressing several security vulnerabilities. The maintainers indicated that future releases may occur more frequently to expedite bug fixes, noting a rise in security reports, many identified with the assistance of AI models.
A significant change in OpenSSH 10.6 is the enablement of the `ssh-mldsa44-ed25519` hybrid post-quantum signature algorithm. Users who previously generated experimental keys using earlier support for this algorithm are advised to regenerate or remove them.
The new release also disables the LZ77 dictionary coder for both the `sshd` server and `ssh` client, making the `Compression` option less effective. This change addresses an attack vector where an adversary controlling input on one channel could potentially recover secrets from another, due to all channels in a session sharing a single compression dictionary. The maintainers recommend using application-level compression, which they state is generally more effective and not susceptible to this particular attack.
To prevent potential shell injection, `ssh` now rejects command-line usernames that contain a dollar sign (`$`) or backslash (`\`). This mitigation aims to prevent untrusted input from being injected into a shell context via features like `ProxyCommand` or `Match exec`. Usernames defined using the `User` directive in configuration files are not affected by this restriction.
Other security enhancements include `sshd` now storing GSSAPI credentials only after successful authentication, preventing the persistence and potential exposure of credentials from failed attempts. The `sftp` client has also been updated to validate server-returned paths more strictly, closing a vulnerability where a malicious server could direct a recursive copy operation outside its intended target directory.
A bug in `ssh-keygen` related to Daylight Saving Time has been fixed, which previously could cause certificate expiry times to be off by up to two hours in certain time zones, such as Antarctica/Troll.
For specific platforms like QNX 6, SCO OpenServer 5, and builds compiled with `disable-fd-passing`, the post-authentication process retains root privileges. Consequently, `GatewayPorts` and `StreamLocalForwarding` are now disabled on these platforms. The project stated that support for these platforms might be removed in the future if a suitable alternative is not found.






