NewsCloud & DevOpsSecurity

OpenSSH 10.6: Compression Killed, PQ Keys Break Now

OpenSSH 10.6 SSH terminal with post-quantum cryptography key symbols

OpenSSH 10.6 shipped October 6 and deliberately broke two things. Not patched — deliberately broke. The first is SSH compression, which had a quiet design flaw researchers turned into a CRIME-style plaintext recovery attack. The second is usernames containing dollar signs or backslashes, which could let a crafted value execute arbitrary commands through ProxyCommand. If you generated experimental post-quantum keys under OpenSSH 10.4, those keys stopped loading silently after you upgraded. Here’s what to audit and what to fix today.

Compression Is Gone (for Good Reason)

The Compression option in SSH has used Deflate — LZ77 plus Huffman coding — since the early days. OpenSSH 10.6 disables the LZ77 dictionary portion and keeps Huffman. The result: SSH compression still exists on paper, but it’s much less effective.

The reason is a side-channel attack by researchers Fabian Bäumer and Marcus Brinkmann from Ruhr University Bochum. In a multiplexed SSH session, all channels shared a single LZ77 compression dictionary. That shared state meant an attacker feeding chosen plaintext into one channel could observe compressed traffic length changes and recover secrets from another channel in the same session. It’s the same family as CRIME and BREACH against TLS — shared compression state is shared attack surface.

OpenSSH removed the shared dictionary entirely rather than trying to isolate dictionaries per channel. For interactive SSH sessions, you won’t notice the difference. For automated jobs moving large volumes of compressible data over constrained links, you might. Move compression to the application layer — pipe through gzip, use rsync --compress, or handle it in your transfer protocol. That’s more effective anyway since it can be tuned to the specific data type.

Post-Quantum Keys: Experimental Is Over, Some Keys Are Silently Broken

OpenSSH 10.4 shipped experimental support for ssh-mldsa44-ed25519@openssh.com — a hybrid signature combining NIST ML-DSA (FIPS 204) with classical Ed25519. OpenSSH 10.6 graduates it to the stable name: ssh-mldsa44-ed25519, no suffix. Keys generated under the old name no longer load. The server silently stops advertising the key type when it can’t find a valid key.

If you deployed experimental PQ keys as host or user keys, regenerate them now:

# Check for old experimental host keys
ls -la /etc/ssh/ssh_host_mldsa44_ed25519*

# Regenerate host key
sudo rm /etc/ssh/ssh_host_mldsa44_ed25519_key*
sudo ssh-keygen -t mldsa44-ed25519 -f /etc/ssh/ssh_host_mldsa44_ed25519_key -N ""
sudo systemctl restart sshd

# For user keys: delete and regenerate, then update authorized_keys on all servers

The CNSA 2.0 deadline for post-quantum migration is January 2027. The hybrid mldsa44-ed25519 approach covers the transition: breaking it requires compromising both ML-DSA and Ed25519 simultaneously, so you’re protected even if ML-DSA has undiscovered weaknesses. The new default WarnWeakCrypto server option logs clients using non-post-quantum-safe key exchanges without blocking them — a useful inventory tool before enforcement arrives.

Username Injection and scp -R: Two More Things to Check

OpenSSH now rejects $ and \ in command-line usernames. The risk: a username from untrusted input landing in ProxyCommand or Match exec could inject shell metacharacters and execute arbitrary commands. The config-file User directive is exempt. If your automation builds SSH commands from external input, validate or sanitize before the call — or use -o User= in config instead.

The scp -R flag — remote-to-remote copy — is now deprecated with a warning. It’s fragile and requires credentials on the intermediate host. Migrate to rsync over SSH before it’s removed in a future release. SFTP also gets tighter path validation against malicious servers steering recursive copies outside the intended target directory.

Why OpenSSH Is Shipping Faster Now

OpenSSH 10.5 dropped five weeks after 10.4 — unusually fast — because AI models were finding vulnerabilities faster than the standard release cycle could process them. OpenSSH 10.6 follows the same pattern. The team has committed to a shorter release cadence, explicitly citing AI-assisted security research. Monthly CVE disclosures across the industry have risen 145% since mid-2024, largely driven by automated tooling. OpenSSH is one of the most scrutinized codebases on the planet, and that scrutiny is now running at machine speed.

Upgrade to 10.6, check your compression config, audit for experimental PQ keys, and watch for WarnWeakCrypto log entries. The next release is probably closer than you expect.

ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *

    More in:News