OpenSSH 10.6 Disables LZ77 Compression to Block 'Crossing the Streams' Plaintext Recovery, Ships SFTP, Injection, and Post-Quantum Fixes
OpenSSH 10.6, released October 6, 2026, disables LZ77 compression to mitigate a cross-channel plaintext recovery attack and hardens SFTP, username handling, GSSAPI, and tunneling, amid a surge of AI-assisted security reports.
Damien Miller announced OpenSSH 10.6 on the oss-security list on October 6, 2026, with the release available from openssh.com. The headline fix disables the LZ77 compression dictionary coder in both ssh and sshd: GBHackers identifies the flaw as the 'Crossing the Streams' plaintext recovery attack by Fabian Bäumer and Marcus Brinkmann, in which shared compression state across multiplexed channels lets attacker-controlled input change ciphertext lengths, creating a chosen-plaintext side channel to recover secrets from another channel. Cyber Security News stresses that the flaw does not break SSH encryption—it exploits pre-encryption length changes—and reports that in a low-noise test an eight-character alphabetic secret needed at most 276 guesses; GBHackers says application-level compression is recommended instead. The client also now rejects command-line usernames containing $ or backslash to limit shell injection through ProxyCommand or Match exec, though Cyber Security News notes the filter does not apply to the User directive in configuration files. GSSAPI credentials are stored only after authentication succeeds, and sftp path checks are tightened so a malicious server cannot steer recursive copies outside the target directory—a flaw Cyber Security News describes as client trust of server-supplied paths rather than unauthenticated server writes. Additional fixes cover authorized_keys tunnel forwarding restrictions, oversized decompressed packets and packet length enforcement, and certificate dates. Help Net Security reports that the hybrid post-quantum signature ssh-mldsa44-ed25519 is enabled, so experimental keys must be regenerated or removed, and GBHackers adds that scp -R is deprecated. All four reports describe a surge of security bug reports, many AI-assisted; oss-security says many of the AI reports have no security impact, while the later outlets say maintainers expect more frequent releases as a result. No report lists CVE identifiers or reports in-the-wild exploitation.
- OpenSSH 10.6 was released October 6, 2026, announced by Damien Miller on the oss-security list and available from openssh.com.
- ssh and sshd disable the LZ77 compression dictionary coder to mitigate 'Crossing the Streams,' a plaintext recovery attack credited to Fabian Bäumer and Marcus Brinkmann (GBHackers).
- The compression flaw exploits shared compression state across multiplexed channels, where attacker-controlled input changes ciphertext lengths, creating a chosen-plaintext side channel to recover secrets from another channel; it does not…
- In a low-noise test, an eight-character alphabetic secret required at most 276 guesses (Cyber Security News).
- The client rejects command-line usernames containing $ or backslash to limit shell injection via ProxyCommand or Match exec; the filter does not apply to the User directive in configuration files (Cyber Security News).
- GSSAPI credentials are stored only after authentication succeeds.
- SFTP path checks are tightened so a malicious server cannot steer recursive copies outside the target directory; the flaw is client trust of server-supplied paths, not unauthenticated server writes (Cyber Security News).
- Further fixes cover authorized_keys tunnel forwarding restrictions, oversized decompressed packets and packet length enforcement, and certificate dates.
Coverage timelineoldest first · each row is one article
- · 2d agoAnnounce: OpenSSH 10.6 released
oss-security· 32
OpenSSH 10.6 is released as the project reports a surge of AI-assisted security bug reports.
- · 1d agoOpenSSH 10.6 enables a post-quantum signature algorithm, so experimental keys need replacing
Help Net Security· 66
OpenSSH 10.6 disables risky compression, blocks shell-injecting usernames, and enables a post-quantum signature.
- · 1d ago