From foo@bar  Tue Oct  6 19:00:04 2026
Format: 1.8
Date: Tue, 06 Oct 2026 18:00:40 +0100
Source: openssh
Binary: openssh-client openssh-client-dbgsym openssh-client-udeb openssh-common openssh-common-dbgsym openssh-server openssh-server-dbgsym openssh-server-udeb openssh-sftp-server openssh-sftp-server-dbgsym openssh-tests openssh-tests-dbgsym ssh ssh-askpass-gnome ssh-askpass-gnome-dbgsym
Architecture: hppa
Version: 1:10.6p1-1
Distribution: sid
Urgency: medium
Maintainer: hppa Build Daemon (paladin) <buildd@paladin.parisc-linux.org>
Changed-By: Colin Watson <cjwatson@debian.org>
Description:
 openssh-client - secure shell (SSH) client, for secure access to remote machines
 openssh-client-udeb - secure shell client for the Debian installer (udeb)
 openssh-common - common files for OpenSSH
 openssh-server - secure shell (SSH) server, for secure access from remote machines
 openssh-server-udeb - secure shell server for the Debian installer (udeb)
 openssh-sftp-server - secure shell (SSH) sftp server module, for SFTP access from remot
 openssh-tests - OpenSSH regression tests
 ssh        - secure shell client and server (metapackage)
 ssh-askpass-gnome - interactive X program to prompt users for a passphrase for ssh-ad
Closes: 1142934 1148080
Changes:
 openssh (1:10.6p1-1) unstable; urgency=medium
 .
   * New upstream release:
     - scp(1): begin deprecating the -R flag, which is used to perform a
       remote-to-remote copy by executing scp on a remote host. This option
       is a fragile optimisation that is difficult to use because it requires
       credentials on the remote host. It also creates security risks if the
       shell quoting rules on the remote system where the copy is performed
       differ from the client's expectations.
 .
       From OpenSSH 10.6, this option will continue to work but will cause a
       deprecation warning to be emitted to standard error. In a future
       release, the option will be ignored and will leave in place the
       default remote-to-remote copy behaviour (copy via the host running
       scp).
     - SECURITY: sftp(1): more strictly validate paths returned from the
       server to avoid some cases where a server could return paths that
       could manipulate a recursive copy operation into writing outside its
       target directory.
     - SECURITY: sshd(8): when GSSAPIAuthentication is in use, only store
       GSSAPI credentials when authentication has succeeded. Avoids a
       situation where credentials from a failed GSSAPIAuthentication attempt
       may persist and be made inappropriately available if another
       authentication subsequently succeeds.
     - SECURITY: sshd(8): reset GSSAPIAuthentication before authentication,
       avoiding state from one authentication attempt being confused with
       that of a later attempt.
     - SECURITY: sshd(8), ssh(1): disable LZ77 dictionary coder to mitigate
       side-channel leaks. A chosen-plaintext attack method exists which
       makes use of dictionary-based compression to recover secrets from one
       channel by interacting with the SSH session's shared compression
       dictionary through another channel.
 .
       Attacker-controlled input can recognizably reflect into the total
       length of transmitted ciphertexts by virtue of LZ77 replacing repeated
       strings with back-references into the SSH session's encoder search
       buffer, which is shared across all channels. For this reason, the
       documentation already recommended against enabling compression for
       connections that share trusted and untrusted traffic.
 .
       This change will reduce the effectiveness of the Compression option.
       Users are encouraged to use application-level compression over the SSH
       protocol where possible, as this will typically be more effective and
       will be completely immune to this type of attack.
     - SECURITY: ssh(1): disallow '$' and '\' characters in usernames entered
       on the command-line to avoid usernames from untrusted sources yielding
       injection in shell context via ProxyCommand, Match exec, etc.
       Usernames specified via the configuration files are not subject to
       this control.
 .
       We continue to recommend against directly exposing ssh(1) and other
       tools' command-lines to untrusted input. Mitigations such as this
       cannot be absolute given the variety of shells and user configurations
       in use.
     - SECURITY: ssh-keygen(1): correct handling of Daylight Saving Time when
       converting dates. Previous handling could cause errors of up to +/- 1
       hour (unless you are in the Antarctica/Troll timezone, where the error
       could be +/- 2 hours). These errors could result in creation of
       certificates with incorrect expiry times.
     - SECURITY: sshd(8), ssh(1): ensure that compressed payloads don't
       inflate past the maximum supported packet length.
     - SECURITY: sshd(8): fully honor the authorized_keys "restrict" keyword,
       which was not being properly applied to tunnel forwarding
       (PermitTunnel, disabled by default).
     - SECURITY: sshd(8): correctly handle some options that accept "none".
       Some options, including AuthorizedPrincipalsFile, were documented as
       accepting "none" as a way to disable them; however, when overridden by
       an sshd_config(5) Match keyword, this argument was being incorrectly
       interpreted as a literal file.
     - All: enable hybrid post-quantum ssh-mldsa44-ed25519 signature
       algorithm. Note that this no longer uses the "@openssh.com" vendor
       extension suffix that the previous experimental implementation used.
       Keys generated with the previous experimental support must be
       regenerated and/or removed.
     - sshd(8): Add the WarnWeakCrypto option to sshd_config(5). This option
       was previously available for the client only. This option is enabled
       by default and will log when the client uses a key agreement scheme
       that is not post-quantum safe.
     - ssh-keygen(1), ssh-add(1): preserve user-verification (PIN or
       biometric) requirement for resident keys loaded from a FIDO token, by
       checking the credential's credProtect policy.
     - ssh(1): include local and remote version strings in the ~I connection
       information display.
     - ssh-add(1): add a -P flag to skip PIN entry for FIDO and PKCS#11
       tokens that do not require it.
     - sftp(1): add '-p' flag for mkdir/lmkdir to create directories as
       required. This flag has similar ergonomics to mkdir(1), and
       previously-existing directories do not cause an error.
     - ssh-keygen(1): add a "hexdump" key export mode that dumps the SSH
       wire-formatted key blob in hex format. Useful when writing
       documentation, tests, etc. E.g. `ssh-keygen -em hexdump -f /key`.
     - ssh(1), sshd(8): ChannelTimeout now accepts timeouts with fractional
       seconds.
     - sshd(8): allow specification of the location of $SSH_AUTH_SOCK used
       for agent forwarding using a new AgentSocketPath option. This supports
       both using a user-specific path, such as the default of a subdirectory
       of $HOME ("user:.ssh/agent"), and the previous approach of allowing
       agent forwarding sockets to be located in a shared directory (e.g.
       "shared:/tmp"). Sockets created in shared directories will be created
       inside a subdirectory with a randomised name.
     - ssh-agent(1): allow specification of agent socket directories using a
       -A flag. It accepts "user:" and "shared:" directory styles similar to
       the sshd AgentSocketPath option.
     - sshd(8): account for public key authentication "key ok" tests
       separately to auth attempts. Add a `PubkeyOptions max-pk-ok:nnnn`
       option to allow a number of PK_OK tests (asking whether the server
       might accept a given public key) that do not count against
       MaxAuthTries, defaulting to 6 attempts. After these attempts are
       exhausted, further attempts count as failed authentications against
       MaxAuthTries. Practically, this allows more keys on disk or held in
       ssh-agent to be checked for use before the server disconnects.
     - ssh(1), sshd(8): extend the existing TCPKeepAlive option to also
       support setting keepalives on sockets created for forwarding
       connections. Previously this option controlled keepalives on the
       connection socket only. TCPKeepAlive "yes" or "transport" enables
       keepalives on the connection socket. "TCPKeepAlive all" additionally
       enables them for forwarding sockets.
     - sshd(8), ssh(1): fix configuration matching on more Turkic languages
       which have disjoint dotted and dotless i/I characters, specifically
       Azerbaijani and Crimean Tatar.
     - ssh(1), sshd(8): don't attempt to set TCP_NODELAY on non-IP/IPv6
       sockets. Eliminates some noise in debug logs.
     - ssh(1): fix case for ssh -G option output.
     - ssh(1), sshd(8): Fix ChannelTimeout specificity; previously a more
       specific channel type (e.g. "session:shell") could clobber a
       user-specified ChannelTimeout if it was less specific (e.g.
       "session").  Also, in some cases, the debug messages were printing 0
       instead of the effective timeout.
     - sftp(1): avoid NULL dereference crash in some circumstances when a
       server fails a stat/lstat operation.
     - sshd(8): close a race condition where a SIGTERM/SIGQUIT would be
       ignored if it was received by the server while it was processing a
       SIGHUP restart request.
     - sshd(8), ssh(1): check key and CA signature types during key parsing
       against allowlists (PubkeyAcceptedAlgorithms, etc) as early as
       possible. This reduces the attack surface presented by disabled
       algorithms.
     - All: switch the fallback implementation of the ed25519 signature
       algorithm used when libcrypto is disabled from SUPERCOP ed25519 to
       libsodium. The libsodium implementation includes a number of
       strictness checks over the original reference implementation we have
       used to this point and a more ergonomic API.
     - ssh-add(1), ssh(1), ssh-keygen(1): fix spin on password entry when the
       program attempting to read a password was started in a background
       process group, with no TTY and with certain signals ignored.
     - scp(1): disallow nul byte in received scp -O filename. This was not
       reachable in normal operation.
     - ssh-keygen(1), ssh(1), sshd(8): implement a maximum number of KDF
       rounds that will be accepted when writing an OpenSSH-format private
       key or when loading one. This limit is set quite high (1M), but
       ensures that a service that is passed a bad key with a ridiculously
       high number of rounds will eventually complete parsing it.
     - ssh-keygen(1): bump the default number of KDF rounds from 24 to 32
       (this is a linear increase, not like bcrypt(3) which is exponential).
     - ssh(1): make StreamLocalBindMask properly respect Host/Match blocks
       and make it first-match-wins as documented.
     - sshd(8): make StreamLocalBindMask properly first-match-wins.
     - sshd(8): don't link sshd against libselinux when SELinux support is
       enabled (note: this library is still linked for the sshd-auth and
       sshd-session helper binaries).
     - sshd(8): restrict mremap(2) flags accepted by the seccomp sandbox.
       Only MREMAP_MAYMOVE is now accepted as other flags may have some
       utility in attack chains.
     - sshd(8): allow PAMServiceName in Match (regressed in 10.4). During the
       refactor of server option parsing, the ability to set PAMServiceName
       in Match blocks was accidentally disabled.
   * Generate MLDSA44-ED25519 host key by default (closes: #1142934).
   * Remove Lintian overrides that now only apply to openssh-gssapi.
   * Remove copyright entry that now only applies to openssh-gssapi.
   * Skip purging if openssh-{client,server}-gssapi is installed (closes:
     #1148080).
Checksums-Sha1:
 8547b9882239109c29eadd2049caacac15c93139 3849792 openssh-client-dbgsym_10.6p1-1_hppa.deb
 f25a612564f3defed33bbecd9277cc961beb08bf 358332 openssh-client-udeb_10.6p1-1_hppa.udeb
 6ebe4ed954c3b7acce0112ce3f34f03f0fb9b588 632228 openssh-client_10.6p1-1_hppa.deb
 2fd5d38c15651f924889a17c6d4b9e5789ab28a0 1738236 openssh-common-dbgsym_10.6p1-1_hppa.deb
 a5ec4f4831c8511ba4479045d659cd12863fa506 465912 openssh-common_10.6p1-1_hppa.deb
 016f97dc32ea0644e2e827022301ec9286cc7d48 2909960 openssh-server-dbgsym_10.6p1-1_hppa.deb
 860d390cd82c444e02eb1d42f7d7648855f9a210 472388 openssh-server-udeb_10.6p1-1_hppa.udeb
 a523f1e5f087146a183470fb09819ac3c7de3e77 543852 openssh-server_10.6p1-1_hppa.deb
 c10339be694c8feef9553d790d9e4b6e964edf83 174796 openssh-sftp-server-dbgsym_10.6p1-1_hppa.deb
 5682a08052032e507524baa2bea026ae775e75c0 66408 openssh-sftp-server_10.6p1-1_hppa.deb
 0d2863e898b0eeed0e156bcc93a4f908a4d1b97a 5209052 openssh-tests-dbgsym_10.6p1-1_hppa.deb
 41991de9f8dbd3cd625f0eed54c93c7296f8c1d6 1280628 openssh-tests_10.6p1-1_hppa.deb
 1152fc5cff11b2d73ec3a415bb748381138d2509 18080 openssh_10.6p1-1_hppa.buildinfo
 fc227da89d8c322026e9e4523846c187f8cddf3e 16644 ssh-askpass-gnome-dbgsym_10.6p1-1_hppa.deb
 800d0e5dd48927f9f8e26fe065531a346a3c2251 14320 ssh-askpass-gnome_10.6p1-1_hppa.deb
 584f8f8826c4e000f6ae015846a7636826c49250 1188 ssh_10.6p1-1_hppa.deb
Checksums-Sha256:
 e2af62f78a9fc1b33df260c11340dccb95c24be998c5509e48269aa7f54609df 3849792 openssh-client-dbgsym_10.6p1-1_hppa.deb
 80778a607ed5282276b03a76c7bf96847e6dc8d0c24ce7732260bb09259ca5a1 358332 openssh-client-udeb_10.6p1-1_hppa.udeb
 95b6e5a5217bdcb4fa3a23a6db3b27646bcf5bc1756b4d51451314676ee63a60 632228 openssh-client_10.6p1-1_hppa.deb
 3329e46c880ae97c979bed868f3c74392f50216022610ef4ed469ea85eb4afd2 1738236 openssh-common-dbgsym_10.6p1-1_hppa.deb
 65d6eabde829ee7f425cde6149e7c0e203f013f4d059ebf4b6d3de5e48e13dcc 465912 openssh-common_10.6p1-1_hppa.deb
 07611d571a443538661844ded497efcea09fbba6481997e92da002f30fafffae 2909960 openssh-server-dbgsym_10.6p1-1_hppa.deb
 5bba5c81e783a84ccb626591bccefc2c5de9bc1dca752ea63f7ae684e1faf14f 472388 openssh-server-udeb_10.6p1-1_hppa.udeb
 f12252b6c69793e2d92a14096b4b598bb9038831a54d831488ae484b4aa58c12 543852 openssh-server_10.6p1-1_hppa.deb
 761045586bd8af04a7d3f9689362192ea455201b4c663ffc11036ff610e72e59 174796 openssh-sftp-server-dbgsym_10.6p1-1_hppa.deb
 fbddd634a4c3d788fcb39e73844135c6a39de881bad04aadee8e66a00b7a59ac 66408 openssh-sftp-server_10.6p1-1_hppa.deb
 d76abaefb0ff7b31943720a40cfe754025e915c15e471cc6331ee78dfc2835f2 5209052 openssh-tests-dbgsym_10.6p1-1_hppa.deb
 aef44c2a4b7bae98166c69aae93992b811975072c6eebaef51173be95a9493df 1280628 openssh-tests_10.6p1-1_hppa.deb
 7f29c63e3b46010ee296b60dea611a53412e1d041d1234d4b62baebd185b403b 18080 openssh_10.6p1-1_hppa.buildinfo
 fbd77ffb6efd3c249f8f60523be67ed7f290497d719304946b60f6bbd887b014 16644 ssh-askpass-gnome-dbgsym_10.6p1-1_hppa.deb
 6a81eb85324ea8df4499ba2356710694eab53a8eed98b95b11b5587e0ed47d71 14320 ssh-askpass-gnome_10.6p1-1_hppa.deb
 800456a908da2d7a205f94c24f24091d474f8c025966621afc9a688c17e850ed 1188 ssh_10.6p1-1_hppa.deb
Files:
 f1665d3007cfc5973a45b43b9cf88a84 3849792 debug optional openssh-client-dbgsym_10.6p1-1_hppa.deb
 a8353a5513124d37ea0f93f0a83d5da1 358332 debian-installer optional openssh-client-udeb_10.6p1-1_hppa.udeb
 59155b2463382fee406aa16c522c3b36 632228 net standard openssh-client_10.6p1-1_hppa.deb
 c94c0e6004fa25f353601d0543e033ca 1738236 debug optional openssh-common-dbgsym_10.6p1-1_hppa.deb
 97ea8b4d337ddc366a1bcbac5c7d90c7 465912 net standard openssh-common_10.6p1-1_hppa.deb
 90e84031af7847d3ac3a33aa17bf428c 2909960 debug optional openssh-server-dbgsym_10.6p1-1_hppa.deb
 92a9fe7390b83bf20443735290f825f7 472388 debian-installer optional openssh-server-udeb_10.6p1-1_hppa.udeb
 b14cff01bb711c8cb633e8347cdcac3d 543852 net optional openssh-server_10.6p1-1_hppa.deb
 82d02564572d9b2808961e759aa1ea67 174796 debug optional openssh-sftp-server-dbgsym_10.6p1-1_hppa.deb
 415d6647678a5867b536b5a659ea3291 66408 net optional openssh-sftp-server_10.6p1-1_hppa.deb
 866b579ccf3743095c095f3c3c275230 5209052 debug optional openssh-tests-dbgsym_10.6p1-1_hppa.deb
 b5a92abe42d0e9ca5b1eff6dfc21ce2c 1280628 net optional openssh-tests_10.6p1-1_hppa.deb
 00e78609f2da759613b4d1981b25f464 18080 net standard openssh_10.6p1-1_hppa.buildinfo
 cc52b275f31009f25f302dd3d8f7614d 16644 debug optional ssh-askpass-gnome-dbgsym_10.6p1-1_hppa.deb
 d77090dfcab5402c04b5c9731db8c93c 14320 gnome optional ssh-askpass-gnome_10.6p1-1_hppa.deb
 8cd4f25ddf83c145ef87e2ed66fda407 1188 net optional ssh_10.6p1-1_hppa.deb
Signed-By: Debian buildd autosigning key for paladin <buildd_hppa-paladin@buildd.debian.org>

