OpenSSH 10.6 Fixes Security Flaws Including SSH Plaintext Recovery Attack
OpenSSH 10.6 patches a cross-channel SSH plaintext recovery attack exploiting shared LZ77 compression state, plus SFTP, GSSAPI, and forwarding fixes.
OpenSSH 10.6, released October 6, 2026, disables the LZ77 compression coder in ssh and sshd to mitigate the 'Crossing the Streams' plaintext recovery attack by Fabian Bäumer and Marcus Brinkmann. The attack exploits shared compression dictionaries across multiplexed channels so attacker-controlled input changes ciphertext lengths, creating a chosen-plaintext side channel to recover secrets. The release also hardens SFTP server path validation, GSSAPI authentication state handling, command-line username filtering to reduce shell injection, packet length enforcement, and authorized_keys tunnel forwarding restrictions. Maintainers are deprecating scp -R and accelerating releases amid rising AI-assisted vulnerability reports.
- Fixes SSH plaintext recovery via shared LZ77 compression state across multiplexed channels
- LZ77 dictionary coder disabled in ssh and sshd; application-level compression recommended
- SFTP path validation blocks malicious servers redirecting recursive copies
- Usernames with dollar signs or backslashes rejected to reduce shell injection risk
- scp -R deprecated; faster release cadence planned amid AI-assisted vulnerability reports
Full article520 words · extracted from gbhackers.com · click to collapse
OpenSSH released version 10.6 on October 6, 2026, to address security vulnerabilities that affect encrypted sessions, file transfers, authentication, and forwarding controls.
This update mitigates a plaintext recovery attack that exploits shared compression states across multiplexed SSH channels and introduces compatibility changes, while accelerating the project’s security release schedule.
OpenSSH 10.6 Fixes Security Flaws
The main fix focuses on research titled “Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels,” by Fabian Bäumer and Marcus Brinkmann. Their attack targets dictionary-based compression that is shared between logical channels within an SSH connection.
The LZ77 compression method replaces repeated strings with references to previously processed data. Because SSH channels share the encoder’s search buffer, attacker-controlled input on one channel can affect ciphertext lengths when it matches sensitive information transmitted through another channel.
These observable differences create a chosen-plaintext side channel that attackers can exploit to recover secrets.
This issue pertains to compression behavior rather than being a direct compromise of SSH encryption. Exploiting this vulnerability requires interaction with the shared compression dictionary through input on a channel controlled by an attacker.
OpenSSH documentation has already warned against enabling compression when both trusted and untrusted traffic share connections.
OpenSSH 10.6 disables the LZ77 dictionary coder in both the `ssh` and `sshd` components. As a result, the Compression option becomes less effective.
Maintainers recommend using application-level compression when possible, noting that it is generally more efficient and immune to this specific cross-channel attack.
The SFTP client now validates server-returned paths more strictly, preventing malicious responses from redirecting recursive copies outside their intended destination directories.
Authentication fixes ensure that GSSAPI credentials are retained only after successful authentication and prevent states from earlier attempts from contaminating subsequent attempts.
Command-line destination usernames containing dollar signs or backslashes are now rejected, which reduces the risk of shell injection when untrusted usernames reach mechanisms like ProxyCommand or Match exec.
Usernames configured through the User directive remain exempt, and maintainers caution that filtering cannot entirely protect against arbitrary shell configurations.
Other fixes include enforcing maximum packet lengths after decompression, correctly applying the `authorized_keys` restriction to tunnel forwarding, and addressing daylight-saving time conversions that could result in incorrect certificate expiration times. Server options that accept ‘none’ also receive corrected handling within Match blocks.
On legacy platforms that require root privileges for terminal allocation without file-descriptor passing, OpenSSH disables GatewayPorts and StreamLocalForwarding to prevent privileged forwarding operations that could bypass user restrictions. Affected systems include QNX 6 and SCO OpenServer 5.
This release also begins deprecating the `scp -R` command, which executes remote-to-remote copies on a remote host and poses credential and shell-quoting risks. While it still functions, it now emits a warning.
Additionally, maintainers plan to release more frequently in response to increasing reports of AI-assisted vulnerabilities. They emphasize the importance of human triage, realistic threat models, test cases, and proposed fixes to differentiate actionable security findings.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.