OpenSSH 10.6 Released with Security Hardening, Post-Quantum Support

OpenSSH 10.6 is out with security fixes, the new hybrid post-quantum ssh-mldsa44-ed25519 algorithm, and several new SSH and SFTP features.

OpenSSH 10.6 has been released with several security fixes, new post-quantum cryptography support, and improvements to SSH, sshd, SFTP, and ssh-agent, part of the widely used OpenSSH suite for secure remote access and file transfers.

One notable change is disabling the LZ77 dictionary coder used for SSH compression. This addresses a chosen-plaintext side-channel attack that could expose sensitive data when attacker-controlled and secret information share the same compression context.

As a result, SSH compression will be less effective. The project recommends application-level compression where possible.

SFTP also gets tighter path validation to prevent a malicious server from causing recursive copy operations outside the intended destination directory. Usernames supplied directly on the ssh command line can no longer contain $ or \, reducing shell-injection risks involving features like ProxyCommand and Match exec.

On the cryptography side, OpenSSH 10.6 enables the hybrid post-quantum ssh-mldsa44-ed25519 signature algorithm. Keys created using the earlier experimental @openssh.com version should be regenerated or removed.

The server also gains WarnWeakCrypto, enabled by default, which logs connections using key exchange methods that are not considered post-quantum safe.

Other additions include mkdir -p support in SFTP, fractional-second values for ChannelTimeout, new controls for SSH agent socket locations, and broader TCP keepalive handling. The default KDF rounds for OpenSSH private keys increased from 24 to 32.

The release also begins deprecating the widely used scp -R. It still works but produces a warning and is expected to be ignored in a future release.

Finally, the OpenSSH team says it plans to publish releases more frequently for now, citing the growing number of security bugs being discovered with AI-assisted tools and the likelihood that attackers could find the same issues independently.

For additional details, see the release notes. OpenSSH 10.6 is now available from the project’s official mirrors, with source packages for both OpenSSH and Portable OpenSSH.

Bobby Borisov

Bobby Borisov

Bobby, an editor-in-chief at Linuxiac, is a Linux professional with over 20 years of experience. With a strong focus on Linux and open-source software, he has worked as a Senior Linux System Administrator, Software Developer, and DevOps Engineer for small and large multinational companies.

Leave a Reply

Your email address will not be published. Required fields are marked *