🔒OpenSSH 10.6 Released with Security Improvements
OpenSSH 10.6: Security First
TL;DR
OpenSSH 10.6 is out with security improvements, stricter username checks, and deprecation of the -R flag. Key changes include disabling LZ77 dictionary coder and stricter handling of usernames.
OpenSSH 10.6 is now available, bringing a slew of security enhancements and bug fixes. The release includes stricter checks for usernames entered on the command line, disallowing '$' and '\' characters to prevent injection attacks. The team also disabled the LZ77 dictionary coder to mitigate side-channel leaks. Additionally, the -R flag in scp(1) is being deprecated due to its complexity and security risks. If you're managing SSH connections, this update is crucial for tightening your security posture.
Key Points
OpenSSH 10.6 released on 2026-10-06 with security improvements and bug fixes.
Disabled LZ77 dictionary coder to mitigate side-channel leaks, enhancing security.
Stricter checks for usernames entered on the command line, disallowing '$' and '\' characters.
Deprecated the -R flag in scp(1) due to complexity and security risks.
Removed support for platforms requiring root privilege for PTY allocation.
Why It Matters
If you manage SSH connections, OpenSSH 10.6's stricter security measures are a must. Disabling the LZ77 coder and tightening username checks significantly reduce the risk of injection attacks. However, the deprecation of the -R flag might require adjustments in your workflows, especially if you rely on remote-to-remote copies.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 3,556 builders reading daily.