OpenSSH 10.6 adds post-quantum signatures, speeds releases
OpenSSH 10.6 was released on October 6. It enables a hybrid post-quantum signature algorithm, weakens the Compression option to block a cross-channel attack, and fixes several other security issues. The maintainers also say they will publish releases more often for the time being.
OpenSSH is the open-source suite behind most remote logins on Linux, BSD and many other systems. It includes the sshd server, the ssh client, and tools such as sftp and ssh-keygen. Administrators running either the server or the client should expect updates on a shorter cycle than usual.
AI-assisted bug reports change the pace
The team said the faster schedule is meant to get bugfixes to users sooner. The project has received a large number of security reports. Many were found by AI models or with AI assistance. In a number of cases, a second researcher later found the same bug independently.
The maintainers drew a clear conclusion. Attackers who do not report bugs to open-source projects, they wrote, "are likely to be able to discover these bugs too."
This matches a wider pattern. Other open-source programs have struggled with the same flood, and Google recently paused its OSS bug bounty over AI-generated reports.
Compression loses its dictionary
Both ssh and sshd now disable the LZ77 dictionary coder, so the Compression option is less effective than before. The change follows research by Fabian Bäumer and Marcus Brinkmann. They described an attack in which someone who controls input on one channel can recover secrets carried on another channel.
The problem comes from how compression works inside a session. All channels share a single compression dictionary. When strings repeat across channels, the length of the ciphertext changes, and that difference leaks information. The maintainers suggest compressing data at the application level instead. They say this is typically more effective and is not affected by the attack.
Usernames with $ or \ are refused
The ssh client now rejects usernames given on the command line if they contain a dollar sign or a backslash. A name taken from an untrusted source could otherwise be used to inject into a shell context through the ProxyCommand or Match exec options.
Usernames set with the User directive in configuration files are not affected. The maintainers note that a mitigation like this cannot be absolute.
Other fixes
Several smaller issues were also addressed:
- sshd now stores GSSAPI credentials only after authentication succeeds. Previously, credentials from a failed attempt could remain and be exposed after a later successful login.
- sftp checks paths returned by the server more strictly. This closes cases where a malicious server could steer a recursive copy outside the intended target directory.
- ssh-keygen handled Daylight Saving Time incorrectly. Certificates could carry expiry times off by up to an hour, or by two hours in the Antarctica/Troll timezone.
On QNX 6, SCO OpenServer 5 and builds made without file descriptor passing, the post-authentication process keeps root privileges. GatewayPorts and StreamLocalForwarding are now disabled on those platforms. The team said support for them will be dropped in future if no alternative is found.
Post-quantum keys need replacing
The release enables the hybrid post-quantum signature algorithm ssh-mldsa44-ed25519. It pairs ML-DSA-44 with the classic Ed25519 scheme. Anyone who generated keys using the earlier experimental support must regenerate or remove them.
Our Take
The most telling part of this release is not a single fix but the explanation behind the new schedule. OpenSSH is among the most carefully reviewed codebases in open source. When its maintainers say AI tools are surfacing bugs fast enough that independent researchers collide on the same findings, that suggests the window between discovery and exploitation is getting shorter. Our earlier reporting showed vulnerability disclosures doubling as AI speeds exploitation, and an AI-found Rejetto HFS flaw was later exploited in the wild.
For defenders, the practical lesson is to treat OpenSSH like a browser: patch quickly and often. Teams that relied on SSH compression should test the impact, and anyone who tried experimental post-quantum keys should rotate them now. It is worth watching whether other core infrastructure projects adopt similar release cadences, and whether the pace holds or settles once the backlog of reports is cleared.
