OpenSSH 10.6 Fixes Security Flaws Including SSH Plaintext Recovery Attack
OpenSSH 10.6 patches a cross-channel SSH plaintext recovery attack exploiting shared LZ77 compression state, plus SFTP, GSSAPI, and forwarding fixes.
OpenSSH 10.6, released October 6, 2026, disables the LZ77 compression coder in ssh and sshd to mitigate the 'Crossing the Streams' plaintext recovery attack by Fabian Bäumer and Marcus Brinkmann. The attack exploits shared compression dictionaries across multiplexed channels so attacker-controlled input changes ciphertext lengths, creating a chosen-plaintext side channel to recover secrets. The release also hardens SFTP server path validation, GSSAPI authentication state handling, command-line username filtering to reduce shell injection, packet length enforcement, and authorized_keys tunnel forwarding restrictions. Maintainers are deprecating scp -R and accelerating releases amid rising AI-assisted vulnerability reports.