Skip to content
openssh.org·

🔒OpenSSH 10.6 Released with Security Improvements

OpenSSH 10.6: Security First

TL;DR

OpenSSH 10.6 is out with security improvements, stricter username checks, and deprecation of the -R flag. Key changes include disabling LZ77 dictionary coder and stricter handling of usernames.

OpenSSH 10.6 is now available, bringing a slew of security enhancements and bug fixes. The release includes stricter checks for usernames entered on the command line, disallowing '$' and '\' characters to prevent injection attacks. The team also disabled the LZ77 dictionary coder to mitigate side-channel leaks. Additionally, the -R flag in scp(1) is being deprecated due to its complexity and security risks. If you're managing SSH connections, this update is crucial for tightening your security posture.

Key Points

1

OpenSSH 10.6 released on 2026-10-06 with security improvements and bug fixes.

2

Disabled LZ77 dictionary coder to mitigate side-channel leaks, enhancing security.

3

Stricter checks for usernames entered on the command line, disallowing '$' and '\' characters.

4

Deprecated the -R flag in scp(1) due to complexity and security risks.

5

Removed support for platforms requiring root privilege for PTY allocation.

Why It Matters

If you manage SSH connections, OpenSSH 10.6's stricter security measures are a must. Disabling the LZ77 coder and tightening username checks significantly reduce the risk of injection attacks. However, the deprecation of the -R flag might require adjustments in your workflows, especially if you rely on remote-to-remote copies.

opensshsecuritysshbugfixesfeatures

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,556 builders reading daily.

Also get