From foo@bar  Tue Oct  6 19:50:05 2026
Format: 1.8
Date: Tue, 06 Oct 2026 18:00:40 +0100
Source: openssh
Binary: openssh-client openssh-client-dbgsym openssh-client-udeb openssh-common openssh-common-dbgsym openssh-server openssh-server-dbgsym openssh-server-udeb openssh-sftp-server openssh-sftp-server-dbgsym openssh-tests openssh-tests-dbgsym ssh ssh-askpass-gnome ssh-askpass-gnome-dbgsym
Architecture: hurd-i386
Version: 1:10.6p1-1
Distribution: sid
Urgency: medium
Maintainer: Debian GNU/Hurd Build Daemon <buildd_hurd-i386-ironforge@buildd.debian.org>
Changed-By: Colin Watson <cjwatson@debian.org>
Description:
 openssh-client - secure shell (SSH) client, for secure access to remote machines
 openssh-client-udeb - secure shell client for the Debian installer (udeb)
 openssh-common - common files for OpenSSH
 openssh-server - secure shell (SSH) server, for secure access from remote machines
 openssh-server-udeb - secure shell server for the Debian installer (udeb)
 openssh-sftp-server - secure shell (SSH) sftp server module, for SFTP access from remot
 openssh-tests - OpenSSH regression tests
 ssh        - secure shell client and server (metapackage)
 ssh-askpass-gnome - interactive X program to prompt users for a passphrase for ssh-ad
Closes: 1142934 1148080
Changes:
 openssh (1:10.6p1-1) unstable; urgency=medium
 .
   * New upstream release:
     - scp(1): begin deprecating the -R flag, which is used to perform a
       remote-to-remote copy by executing scp on a remote host. This option
       is a fragile optimisation that is difficult to use because it requires
       credentials on the remote host. It also creates security risks if the
       shell quoting rules on the remote system where the copy is performed
       differ from the client's expectations.
 .
       From OpenSSH 10.6, this option will continue to work but will cause a
       deprecation warning to be emitted to standard error. In a future
       release, the option will be ignored and will leave in place the
       default remote-to-remote copy behaviour (copy via the host running
       scp).
     - SECURITY: sftp(1): more strictly validate paths returned from the
       server to avoid some cases where a server could return paths that
       could manipulate a recursive copy operation into writing outside its
       target directory.
     - SECURITY: sshd(8): when GSSAPIAuthentication is in use, only store
       GSSAPI credentials when authentication has succeeded. Avoids a
       situation where credentials from a failed GSSAPIAuthentication attempt
       may persist and be made inappropriately available if another
       authentication subsequently succeeds.
     - SECURITY: sshd(8): reset GSSAPIAuthentication before authentication,
       avoiding state from one authentication attempt being confused with
       that of a later attempt.
     - SECURITY: sshd(8), ssh(1): disable LZ77 dictionary coder to mitigate
       side-channel leaks. A chosen-plaintext attack method exists which
       makes use of dictionary-based compression to recover secrets from one
       channel by interacting with the SSH session's shared compression
       dictionary through another channel.
 .
       Attacker-controlled input can recognizably reflect into the total
       length of transmitted ciphertexts by virtue of LZ77 replacing repeated
       strings with back-references into the SSH session's encoder search
       buffer, which is shared across all channels. For this reason, the
       documentation already recommended against enabling compression for
       connections that share trusted and untrusted traffic.
 .
       This change will reduce the effectiveness of the Compression option.
       Users are encouraged to use application-level compression over the SSH
       protocol where possible, as this will typically be more effective and
       will be completely immune to this type of attack.
     - SECURITY: ssh(1): disallow '$' and '\' characters in usernames entered
       on the command-line to avoid usernames from untrusted sources yielding
       injection in shell context via ProxyCommand, Match exec, etc.
       Usernames specified via the configuration files are not subject to
       this control.
 .
       We continue to recommend against directly exposing ssh(1) and other
       tools' command-lines to untrusted input. Mitigations such as this
       cannot be absolute given the variety of shells and user configurations
       in use.
     - SECURITY: ssh-keygen(1): correct handling of Daylight Saving Time when
       converting dates. Previous handling could cause errors of up to +/- 1
       hour (unless you are in the Antarctica/Troll timezone, where the error
       could be +/- 2 hours). These errors could result in creation of
       certificates with incorrect expiry times.
     - SECURITY: sshd(8), ssh(1): ensure that compressed payloads don't
       inflate past the maximum supported packet length.
     - SECURITY: sshd(8): fully honor the authorized_keys "restrict" keyword,
       which was not being properly applied to tunnel forwarding
       (PermitTunnel, disabled by default).
     - SECURITY: sshd(8): correctly handle some options that accept "none".
       Some options, including AuthorizedPrincipalsFile, were documented as
       accepting "none" as a way to disable them; however, when overridden by
       an sshd_config(5) Match keyword, this argument was being incorrectly
       interpreted as a literal file.
     - All: enable hybrid post-quantum ssh-mldsa44-ed25519 signature
       algorithm. Note that this no longer uses the "@openssh.com" vendor
       extension suffix that the previous experimental implementation used.
       Keys generated with the previous experimental support must be
       regenerated and/or removed.
     - sshd(8): Add the WarnWeakCrypto option to sshd_config(5). This option
       was previously available for the client only. This option is enabled
       by default and will log when the client uses a key agreement scheme
       that is not post-quantum safe.
     - ssh-keygen(1), ssh-add(1): preserve user-verification (PIN or
       biometric) requirement for resident keys loaded from a FIDO token, by
       checking the credential's credProtect policy.
     - ssh(1): include local and remote version strings in the ~I connection
       information display.
     - ssh-add(1): add a -P flag to skip PIN entry for FIDO and PKCS#11
       tokens that do not require it.
     - sftp(1): add '-p' flag for mkdir/lmkdir to create directories as
       required. This flag has similar ergonomics to mkdir(1), and
       previously-existing directories do not cause an error.
     - ssh-keygen(1): add a "hexdump" key export mode that dumps the SSH
       wire-formatted key blob in hex format. Useful when writing
       documentation, tests, etc. E.g. `ssh-keygen -em hexdump -f /key`.
     - ssh(1), sshd(8): ChannelTimeout now accepts timeouts with fractional
       seconds.
     - sshd(8): allow specification of the location of $SSH_AUTH_SOCK used
       for agent forwarding using a new AgentSocketPath option. This supports
       both using a user-specific path, such as the default of a subdirectory
       of $HOME ("user:.ssh/agent"), and the previous approach of allowing
       agent forwarding sockets to be located in a shared directory (e.g.
       "shared:/tmp"). Sockets created in shared directories will be created
       inside a subdirectory with a randomised name.
     - ssh-agent(1): allow specification of agent socket directories using a
       -A flag. It accepts "user:" and "shared:" directory styles similar to
       the sshd AgentSocketPath option.
     - sshd(8): account for public key authentication "key ok" tests
       separately to auth attempts. Add a `PubkeyOptions max-pk-ok:nnnn`
       option to allow a number of PK_OK tests (asking whether the server
       might accept a given public key) that do not count against
       MaxAuthTries, defaulting to 6 attempts. After these attempts are
       exhausted, further attempts count as failed authentications against
       MaxAuthTries. Practically, this allows more keys on disk or held in
       ssh-agent to be checked for use before the server disconnects.
     - ssh(1), sshd(8): extend the existing TCPKeepAlive option to also
       support setting keepalives on sockets created for forwarding
       connections. Previously this option controlled keepalives on the
       connection socket only. TCPKeepAlive "yes" or "transport" enables
       keepalives on the connection socket. "TCPKeepAlive all" additionally
       enables them for forwarding sockets.
     - sshd(8), ssh(1): fix configuration matching on more Turkic languages
       which have disjoint dotted and dotless i/I characters, specifically
       Azerbaijani and Crimean Tatar.
     - ssh(1), sshd(8): don't attempt to set TCP_NODELAY on non-IP/IPv6
       sockets. Eliminates some noise in debug logs.
     - ssh(1): fix case for ssh -G option output.
     - ssh(1), sshd(8): Fix ChannelTimeout specificity; previously a more
       specific channel type (e.g. "session:shell") could clobber a
       user-specified ChannelTimeout if it was less specific (e.g.
       "session").  Also, in some cases, the debug messages were printing 0
       instead of the effective timeout.
     - sftp(1): avoid NULL dereference crash in some circumstances when a
       server fails a stat/lstat operation.
     - sshd(8): close a race condition where a SIGTERM/SIGQUIT would be
       ignored if it was received by the server while it was processing a
       SIGHUP restart request.
     - sshd(8), ssh(1): check key and CA signature types during key parsing
       against allowlists (PubkeyAcceptedAlgorithms, etc) as early as
       possible. This reduces the attack surface presented by disabled
       algorithms.
     - All: switch the fallback implementation of the ed25519 signature
       algorithm used when libcrypto is disabled from SUPERCOP ed25519 to
       libsodium. The libsodium implementation includes a number of
       strictness checks over the original reference implementation we have
       used to this point and a more ergonomic API.
     - ssh-add(1), ssh(1), ssh-keygen(1): fix spin on password entry when the
       program attempting to read a password was started in a background
       process group, with no TTY and with certain signals ignored.
     - scp(1): disallow nul byte in received scp -O filename. This was not
       reachable in normal operation.
     - ssh-keygen(1), ssh(1), sshd(8): implement a maximum number of KDF
       rounds that will be accepted when writing an OpenSSH-format private
       key or when loading one. This limit is set quite high (1M), but
       ensures that a service that is passed a bad key with a ridiculously
       high number of rounds will eventually complete parsing it.
     - ssh-keygen(1): bump the default number of KDF rounds from 24 to 32
       (this is a linear increase, not like bcrypt(3) which is exponential).
     - ssh(1): make StreamLocalBindMask properly respect Host/Match blocks
       and make it first-match-wins as documented.
     - sshd(8): make StreamLocalBindMask properly first-match-wins.
     - sshd(8): don't link sshd against libselinux when SELinux support is
       enabled (note: this library is still linked for the sshd-auth and
       sshd-session helper binaries).
     - sshd(8): restrict mremap(2) flags accepted by the seccomp sandbox.
       Only MREMAP_MAYMOVE is now accepted as other flags may have some
       utility in attack chains.
     - sshd(8): allow PAMServiceName in Match (regressed in 10.4). During the
       refactor of server option parsing, the ability to set PAMServiceName
       in Match blocks was accidentally disabled.
   * Generate MLDSA44-ED25519 host key by default (closes: #1142934).
   * Remove Lintian overrides that now only apply to openssh-gssapi.
   * Remove copyright entry that now only applies to openssh-gssapi.
   * Skip purging if openssh-{client,server}-gssapi is installed (closes:
     #1148080).
Checksums-Sha1:
 6c7db30f693e36fbea9f310af49eb7c23848701a 3657432 openssh-client-dbgsym_10.6p1-1_hurd-i386.deb
 614d070cbd2cbd29576f47fd68691fb311e2ff16 362724 openssh-client-udeb_10.6p1-1_hurd-i386.udeb
 11e7dc1f3ea02d8327d3893c414d298fe7353fa2 741780 openssh-client_10.6p1-1_hurd-i386.deb
 b41f2d3e04f539939f420397e15e4cbd3803fedb 1654100 openssh-common-dbgsym_10.6p1-1_hurd-i386.deb
 929cdc2d2acedbace93185ddc8c2398ee116381b 507912 openssh-common_10.6p1-1_hurd-i386.deb
 f32d913bde7faf451961f1d02315180d0c59c58b 2741680 openssh-server-dbgsym_10.6p1-1_hurd-i386.deb
 5490a67c3b851c1f2407a8c821edfe9949ddd6c2 495548 openssh-server-udeb_10.6p1-1_hurd-i386.udeb
 07b758e6d0ab6a4d5c76fa705945dcd27a055b9b 632508 openssh-server_10.6p1-1_hurd-i386.deb
 45f5aaea0a8fa40ceaf34e96dbdc5e3400f752cb 140492 openssh-sftp-server-dbgsym_10.6p1-1_hurd-i386.deb
 a77a5228cdbd66a6c2aff3826a1b195d95251b4d 73584 openssh-sftp-server_10.6p1-1_hurd-i386.deb
 cd388d1f47634c4807f52eb92509766929195ff4 4848660 openssh-tests-dbgsym_10.6p1-1_hurd-i386.deb
 df324620fda17d8644c6c1dd96386772c8f5c465 1311964 openssh-tests_10.6p1-1_hurd-i386.deb
 9a0cf4a183ce803c110fc48cc6d12c7e2c441cc6 17783 openssh_10.6p1-1_hurd-i386.buildinfo
 f6e99f2de36eaeb1cc131b061fa7686bf66b88b1 16448 ssh-askpass-gnome-dbgsym_10.6p1-1_hurd-i386.deb
 0688cf50d04206478174e8359e679917559f2717 14512 ssh-askpass-gnome_10.6p1-1_hurd-i386.deb
 84f035d0d2ce29adf4aa5d8c397d4ec7bbeed3b6 1192 ssh_10.6p1-1_hurd-i386.deb
Checksums-Sha256:
 9b9804da59038b975b0d22761c29b1ad118ec6b51084fb9a56f26702b693eb9e 3657432 openssh-client-dbgsym_10.6p1-1_hurd-i386.deb
 e25232d5e9d755fde84946d2c05b14d658b5dd9275c262f506cc85c8e11d779b 362724 openssh-client-udeb_10.6p1-1_hurd-i386.udeb
 84f1220168658eff21108cd9771df3354d73d71e35415ffcf761e66092d14abc 741780 openssh-client_10.6p1-1_hurd-i386.deb
 e03cc557666baaf21ea8693b5ecc215d951a341cf832914ca7c8a99157cbc86f 1654100 openssh-common-dbgsym_10.6p1-1_hurd-i386.deb
 a030b3e3155b3334db4c305773ab33cd9dcc952cf84129d955643568b49b9c23 507912 openssh-common_10.6p1-1_hurd-i386.deb
 e535b9e21e522f8a913ea78a58a0ffc0d99ce21bda56e7a1bb3c128b79b0b521 2741680 openssh-server-dbgsym_10.6p1-1_hurd-i386.deb
 25fc0bcaf2dc2ea6dcbe13846049042d3869d247893ac2c452b822fbb1a70071 495548 openssh-server-udeb_10.6p1-1_hurd-i386.udeb
 06b6837d88af274769978c5376f32a2594784e0819236767220ce361c8ebda68 632508 openssh-server_10.6p1-1_hurd-i386.deb
 9c2c0726d7d34a4dc810b0c27b091184653cb855e780fec560906d6e5e3c4ae9 140492 openssh-sftp-server-dbgsym_10.6p1-1_hurd-i386.deb
 e55aaac605940b39d0b3e2fda3f68a67e9103ef474677485d304f9483e00505b 73584 openssh-sftp-server_10.6p1-1_hurd-i386.deb
 a99fdb110c72f71836d72d0866f72f6b87eed6e51e8ea561640b0a7fd096c687 4848660 openssh-tests-dbgsym_10.6p1-1_hurd-i386.deb
 c76f25dbabf4574363dba8c246d331c78a8a58330a419b3f559ab84e50cb7575 1311964 openssh-tests_10.6p1-1_hurd-i386.deb
 a3d9e24ebfe44cbd6e5e7cd014ac1c06d4c435e3c3292bbb8df83b9f61f937c8 17783 openssh_10.6p1-1_hurd-i386.buildinfo
 4cd0fa598bcb1bfaada2d7efd096adc1466c1e6aabb83ca9bfc3b585869f3120 16448 ssh-askpass-gnome-dbgsym_10.6p1-1_hurd-i386.deb
 2c26707de62adf4ff338a42d8523c4d52ae1e4ad35d6044046fc81b628fc29c7 14512 ssh-askpass-gnome_10.6p1-1_hurd-i386.deb
 5a25dfa030c8118d753fab16e14ae8a9595ae5c4b1bc07068b381b4653d88029 1192 ssh_10.6p1-1_hurd-i386.deb
Files:
 c98424cfaacb1461c762d6c91c1d8539 3657432 debug optional openssh-client-dbgsym_10.6p1-1_hurd-i386.deb
 530ba53c64bae133b7b4af54ca162dd0 362724 debian-installer optional openssh-client-udeb_10.6p1-1_hurd-i386.udeb
 13f4607e923909b03feff47b11e94d19 741780 net standard openssh-client_10.6p1-1_hurd-i386.deb
 5ce35440f6cee541b3bcebd974a1d98b 1654100 debug optional openssh-common-dbgsym_10.6p1-1_hurd-i386.deb
 2fa6289174e78620affce7fb513a142a 507912 net standard openssh-common_10.6p1-1_hurd-i386.deb
 8b6ab2d14d26e3e737d001e290b870e9 2741680 debug optional openssh-server-dbgsym_10.6p1-1_hurd-i386.deb
 2bbb70cab892f724cdaded642993130d 495548 debian-installer optional openssh-server-udeb_10.6p1-1_hurd-i386.udeb
 6dd078a8bf4b0cda3a719a9b3d3be06f 632508 net optional openssh-server_10.6p1-1_hurd-i386.deb
 e33962a1b9ea72af3ed098d3f815c290 140492 debug optional openssh-sftp-server-dbgsym_10.6p1-1_hurd-i386.deb
 4b1445a100e8e2ad78c1f930177dd221 73584 net optional openssh-sftp-server_10.6p1-1_hurd-i386.deb
 8454975f9c541397524e394ae0fc73d3 4848660 debug optional openssh-tests-dbgsym_10.6p1-1_hurd-i386.deb
 4669ea485c04506339ba0d438d67a0ac 1311964 net optional openssh-tests_10.6p1-1_hurd-i386.deb
 d72a322d65a7843498ea77e965d984e1 17783 net standard openssh_10.6p1-1_hurd-i386.buildinfo
 9ab8b740042fa680a49117eea76d70a8 16448 debug optional ssh-askpass-gnome-dbgsym_10.6p1-1_hurd-i386.deb
 1849dee218d311ef7f0839b9d0a40cd7 14512 gnome optional ssh-askpass-gnome_10.6p1-1_hurd-i386.deb
 ee7a0a90f26bc544d1416c6cac6c8f26 1192 net optional ssh_10.6p1-1_hurd-i386.deb
Signed-By: buildd autosigning key ironforge <buildd_hurd-i386-ironforge@buildd.debian.org>

