From foo@bar  Tue Oct  6 20:50:03 2026
Format: 1.8
Date: Tue, 06 Oct 2026 18:00:40 +0100
Source: openssh
Binary: openssh-client openssh-client-dbgsym openssh-client-udeb openssh-common openssh-common-dbgsym openssh-server openssh-server-dbgsym openssh-server-udeb openssh-sftp-server openssh-sftp-server-dbgsym openssh-tests openssh-tests-dbgsym ssh ssh-askpass-gnome ssh-askpass-gnome-dbgsym
Architecture: sh4
Version: 1:10.6p1-1
Distribution: sid
Urgency: medium
Maintainer: sh4 Build Daemon (sh4-do-02) <buildd@sh4-do-02.buildd.org>
Changed-By: Colin Watson <cjwatson@debian.org>
Description:
 openssh-client - secure shell (SSH) client, for secure access to remote machines
 openssh-client-udeb - secure shell client for the Debian installer (udeb)
 openssh-common - common files for OpenSSH
 openssh-server - secure shell (SSH) server, for secure access from remote machines
 openssh-server-udeb - secure shell server for the Debian installer (udeb)
 openssh-sftp-server - secure shell (SSH) sftp server module, for SFTP access from remot
 openssh-tests - OpenSSH regression tests
 ssh        - secure shell client and server (metapackage)
 ssh-askpass-gnome - interactive X program to prompt users for a passphrase for ssh-ad
Closes: 1142934 1148080
Changes:
 openssh (1:10.6p1-1) unstable; urgency=medium
 .
   * New upstream release:
     - scp(1): begin deprecating the -R flag, which is used to perform a
       remote-to-remote copy by executing scp on a remote host. This option
       is a fragile optimisation that is difficult to use because it requires
       credentials on the remote host. It also creates security risks if the
       shell quoting rules on the remote system where the copy is performed
       differ from the client's expectations.
 .
       From OpenSSH 10.6, this option will continue to work but will cause a
       deprecation warning to be emitted to standard error. In a future
       release, the option will be ignored and will leave in place the
       default remote-to-remote copy behaviour (copy via the host running
       scp).
     - SECURITY: sftp(1): more strictly validate paths returned from the
       server to avoid some cases where a server could return paths that
       could manipulate a recursive copy operation into writing outside its
       target directory.
     - SECURITY: sshd(8): when GSSAPIAuthentication is in use, only store
       GSSAPI credentials when authentication has succeeded. Avoids a
       situation where credentials from a failed GSSAPIAuthentication attempt
       may persist and be made inappropriately available if another
       authentication subsequently succeeds.
     - SECURITY: sshd(8): reset GSSAPIAuthentication before authentication,
       avoiding state from one authentication attempt being confused with
       that of a later attempt.
     - SECURITY: sshd(8), ssh(1): disable LZ77 dictionary coder to mitigate
       side-channel leaks. A chosen-plaintext attack method exists which
       makes use of dictionary-based compression to recover secrets from one
       channel by interacting with the SSH session's shared compression
       dictionary through another channel.
 .
       Attacker-controlled input can recognizably reflect into the total
       length of transmitted ciphertexts by virtue of LZ77 replacing repeated
       strings with back-references into the SSH session's encoder search
       buffer, which is shared across all channels. For this reason, the
       documentation already recommended against enabling compression for
       connections that share trusted and untrusted traffic.
 .
       This change will reduce the effectiveness of the Compression option.
       Users are encouraged to use application-level compression over the SSH
       protocol where possible, as this will typically be more effective and
       will be completely immune to this type of attack.
     - SECURITY: ssh(1): disallow '$' and '\' characters in usernames entered
       on the command-line to avoid usernames from untrusted sources yielding
       injection in shell context via ProxyCommand, Match exec, etc.
       Usernames specified via the configuration files are not subject to
       this control.
 .
       We continue to recommend against directly exposing ssh(1) and other
       tools' command-lines to untrusted input. Mitigations such as this
       cannot be absolute given the variety of shells and user configurations
       in use.
     - SECURITY: ssh-keygen(1): correct handling of Daylight Saving Time when
       converting dates. Previous handling could cause errors of up to +/- 1
       hour (unless you are in the Antarctica/Troll timezone, where the error
       could be +/- 2 hours). These errors could result in creation of
       certificates with incorrect expiry times.
     - SECURITY: sshd(8), ssh(1): ensure that compressed payloads don't
       inflate past the maximum supported packet length.
     - SECURITY: sshd(8): fully honor the authorized_keys "restrict" keyword,
       which was not being properly applied to tunnel forwarding
       (PermitTunnel, disabled by default).
     - SECURITY: sshd(8): correctly handle some options that accept "none".
       Some options, including AuthorizedPrincipalsFile, were documented as
       accepting "none" as a way to disable them; however, when overridden by
       an sshd_config(5) Match keyword, this argument was being incorrectly
       interpreted as a literal file.
     - All: enable hybrid post-quantum ssh-mldsa44-ed25519 signature
       algorithm. Note that this no longer uses the "@openssh.com" vendor
       extension suffix that the previous experimental implementation used.
       Keys generated with the previous experimental support must be
       regenerated and/or removed.
     - sshd(8): Add the WarnWeakCrypto option to sshd_config(5). This option
       was previously available for the client only. This option is enabled
       by default and will log when the client uses a key agreement scheme
       that is not post-quantum safe.
     - ssh-keygen(1), ssh-add(1): preserve user-verification (PIN or
       biometric) requirement for resident keys loaded from a FIDO token, by
       checking the credential's credProtect policy.
     - ssh(1): include local and remote version strings in the ~I connection
       information display.
     - ssh-add(1): add a -P flag to skip PIN entry for FIDO and PKCS#11
       tokens that do not require it.
     - sftp(1): add '-p' flag for mkdir/lmkdir to create directories as
       required. This flag has similar ergonomics to mkdir(1), and
       previously-existing directories do not cause an error.
     - ssh-keygen(1): add a "hexdump" key export mode that dumps the SSH
       wire-formatted key blob in hex format. Useful when writing
       documentation, tests, etc. E.g. `ssh-keygen -em hexdump -f /key`.
     - ssh(1), sshd(8): ChannelTimeout now accepts timeouts with fractional
       seconds.
     - sshd(8): allow specification of the location of $SSH_AUTH_SOCK used
       for agent forwarding using a new AgentSocketPath option. This supports
       both using a user-specific path, such as the default of a subdirectory
       of $HOME ("user:.ssh/agent"), and the previous approach of allowing
       agent forwarding sockets to be located in a shared directory (e.g.
       "shared:/tmp"). Sockets created in shared directories will be created
       inside a subdirectory with a randomised name.
     - ssh-agent(1): allow specification of agent socket directories using a
       -A flag. It accepts "user:" and "shared:" directory styles similar to
       the sshd AgentSocketPath option.
     - sshd(8): account for public key authentication "key ok" tests
       separately to auth attempts. Add a `PubkeyOptions max-pk-ok:nnnn`
       option to allow a number of PK_OK tests (asking whether the server
       might accept a given public key) that do not count against
       MaxAuthTries, defaulting to 6 attempts. After these attempts are
       exhausted, further attempts count as failed authentications against
       MaxAuthTries. Practically, this allows more keys on disk or held in
       ssh-agent to be checked for use before the server disconnects.
     - ssh(1), sshd(8): extend the existing TCPKeepAlive option to also
       support setting keepalives on sockets created for forwarding
       connections. Previously this option controlled keepalives on the
       connection socket only. TCPKeepAlive "yes" or "transport" enables
       keepalives on the connection socket. "TCPKeepAlive all" additionally
       enables them for forwarding sockets.
     - sshd(8), ssh(1): fix configuration matching on more Turkic languages
       which have disjoint dotted and dotless i/I characters, specifically
       Azerbaijani and Crimean Tatar.
     - ssh(1), sshd(8): don't attempt to set TCP_NODELAY on non-IP/IPv6
       sockets. Eliminates some noise in debug logs.
     - ssh(1): fix case for ssh -G option output.
     - ssh(1), sshd(8): Fix ChannelTimeout specificity; previously a more
       specific channel type (e.g. "session:shell") could clobber a
       user-specified ChannelTimeout if it was less specific (e.g.
       "session").  Also, in some cases, the debug messages were printing 0
       instead of the effective timeout.
     - sftp(1): avoid NULL dereference crash in some circumstances when a
       server fails a stat/lstat operation.
     - sshd(8): close a race condition where a SIGTERM/SIGQUIT would be
       ignored if it was received by the server while it was processing a
       SIGHUP restart request.
     - sshd(8), ssh(1): check key and CA signature types during key parsing
       against allowlists (PubkeyAcceptedAlgorithms, etc) as early as
       possible. This reduces the attack surface presented by disabled
       algorithms.
     - All: switch the fallback implementation of the ed25519 signature
       algorithm used when libcrypto is disabled from SUPERCOP ed25519 to
       libsodium. The libsodium implementation includes a number of
       strictness checks over the original reference implementation we have
       used to this point and a more ergonomic API.
     - ssh-add(1), ssh(1), ssh-keygen(1): fix spin on password entry when the
       program attempting to read a password was started in a background
       process group, with no TTY and with certain signals ignored.
     - scp(1): disallow nul byte in received scp -O filename. This was not
       reachable in normal operation.
     - ssh-keygen(1), ssh(1), sshd(8): implement a maximum number of KDF
       rounds that will be accepted when writing an OpenSSH-format private
       key or when loading one. This limit is set quite high (1M), but
       ensures that a service that is passed a bad key with a ridiculously
       high number of rounds will eventually complete parsing it.
     - ssh-keygen(1): bump the default number of KDF rounds from 24 to 32
       (this is a linear increase, not like bcrypt(3) which is exponential).
     - ssh(1): make StreamLocalBindMask properly respect Host/Match blocks
       and make it first-match-wins as documented.
     - sshd(8): make StreamLocalBindMask properly first-match-wins.
     - sshd(8): don't link sshd against libselinux when SELinux support is
       enabled (note: this library is still linked for the sshd-auth and
       sshd-session helper binaries).
     - sshd(8): restrict mremap(2) flags accepted by the seccomp sandbox.
       Only MREMAP_MAYMOVE is now accepted as other flags may have some
       utility in attack chains.
     - sshd(8): allow PAMServiceName in Match (regressed in 10.4). During the
       refactor of server option parsing, the ability to set PAMServiceName
       in Match blocks was accidentally disabled.
   * Generate MLDSA44-ED25519 host key by default (closes: #1142934).
   * Remove Lintian overrides that now only apply to openssh-gssapi.
   * Remove copyright entry that now only applies to openssh-gssapi.
   * Skip purging if openssh-{client,server}-gssapi is installed (closes:
     #1148080).
Checksums-Sha1:
 1f6c1642d78ef3939e34a3c15a45f10747d48d50 4798092 openssh-client-dbgsym_10.6p1-1_sh4.deb
 efb66ddd69741537d9ad28eeda1757c8f44b5317 356688 openssh-client-udeb_10.6p1-1_sh4.udeb
 0165983ab69cec62c3577f07761c807e75806bbf 616508 openssh-client_10.6p1-1_sh4.deb
 96d881171f7169ef39fc340ba53e60351a725225 2124740 openssh-common-dbgsym_10.6p1-1_sh4.deb
 1b0605f3c9acd5cc10e59c571fc2ee3908053ed8 465344 openssh-common_10.6p1-1_sh4.deb
 99b1f6c1a65c25dc2cd6660ac231857d31156809 3624724 openssh-server-dbgsym_10.6p1-1_sh4.deb
 512a30dab61a06cb7fa4a0fca6f8cd3d4ec9d4d0 444776 openssh-server-udeb_10.6p1-1_sh4.udeb
 0cb53a9353a7a0d0abb2042fd224a7403a4bae26 528744 openssh-server_10.6p1-1_sh4.deb
 99d7263ce48421e922c33e25a19af0349c8a6482 201160 openssh-sftp-server-dbgsym_10.6p1-1_sh4.deb
 0161f003a781fa8980dba1b6b4305d5fa2b2a0d1 66568 openssh-sftp-server_10.6p1-1_sh4.deb
 8eb159524d8816ec602e55d18663df1b23780526 6395648 openssh-tests-dbgsym_10.6p1-1_sh4.deb
 d0ad40b69fe1e6c3989a0dee7c46089a06fa843b 1166116 openssh-tests_10.6p1-1_sh4.deb
 0421ac6ebbf7593307c2ba3764b1677fa348428b 18117 openssh_10.6p1-1_sh4.buildinfo
 2e5227afb65baed31a987800b7b48bdef23eadb3 17992 ssh-askpass-gnome-dbgsym_10.6p1-1_sh4.deb
 dad8ac42462b22b31e1e9945b6d2e241b67a86f2 14652 ssh-askpass-gnome_10.6p1-1_sh4.deb
 e1bc516c161f8c8ea5207a11f57ea0ad8cde4df3 1188 ssh_10.6p1-1_sh4.deb
Checksums-Sha256:
 77a65688653218992460681e2165e17632db6dc255ce035d122fda10229ee274 4798092 openssh-client-dbgsym_10.6p1-1_sh4.deb
 560909320b4767cf1a2ed463e5e8d2b670ccfe7b0c24daf8a33c2ff860c3565b 356688 openssh-client-udeb_10.6p1-1_sh4.udeb
 bd7bbe8bfcea97ce9252f72a3e4c38a98fbfa1e56fd646ea6c270deac7d00e5e 616508 openssh-client_10.6p1-1_sh4.deb
 8467949bf462e88648df18669daa6c3fbf68531f908f8d11f8bd73fd65ce80dc 2124740 openssh-common-dbgsym_10.6p1-1_sh4.deb
 2deca1e7108f1d17ab533aded940e157d595482b2ccfa18822ba4cbafff2c642 465344 openssh-common_10.6p1-1_sh4.deb
 8833ab4dfbfc5e28c26f3f3fd7c1353bf5c278bdb4a6321cf7a64e952053ba2d 3624724 openssh-server-dbgsym_10.6p1-1_sh4.deb
 099193a57fdeb26aa214ba089b7a340809977e5ee15cbd2490a194e8cc4e619f 444776 openssh-server-udeb_10.6p1-1_sh4.udeb
 c1195c370edec2b9cb95f5c23281f6d6cd84d2b8c42d738e9c9e9c485d557a05 528744 openssh-server_10.6p1-1_sh4.deb
 0eb9b4901440847384b60306d300a5b43ff27f53ebddef37a3f956020550aa75 201160 openssh-sftp-server-dbgsym_10.6p1-1_sh4.deb
 21a68db465e63c827bd833d4f306a6a86160456ce3fa9513aa9f0e01c18b73d1 66568 openssh-sftp-server_10.6p1-1_sh4.deb
 189f2e96db10c935a8db61eb20b9d0601d46fba7095abff39556fc83ba03bb57 6395648 openssh-tests-dbgsym_10.6p1-1_sh4.deb
 e3287881aa4a49941ef288862c3ec3dd9a52d4eb7fb6e16f1d40cbd741d627d4 1166116 openssh-tests_10.6p1-1_sh4.deb
 4e834b6b4931d6d7b84c2c24168692a54d32640568e3d331b1f8832a53436766 18117 openssh_10.6p1-1_sh4.buildinfo
 2d09b409de678a44294d51b2bee071e76a6a95bacc51b05ce6cc940721a02577 17992 ssh-askpass-gnome-dbgsym_10.6p1-1_sh4.deb
 2e9e0207f2a9218518bae7c1ee15bbd26b7618a117db6c9dbf8e6e65cf8f52d0 14652 ssh-askpass-gnome_10.6p1-1_sh4.deb
 39e1a038eeae18e5a83ebe21c4092f23e83d779e43bfce3302da7b8e1d88c2d2 1188 ssh_10.6p1-1_sh4.deb
Files:
 19f2716778f525de2712ca36c195ca63 4798092 debug optional openssh-client-dbgsym_10.6p1-1_sh4.deb
 db00b451cce616c32d0e0dd52da6ba6b 356688 debian-installer optional openssh-client-udeb_10.6p1-1_sh4.udeb
 78860488b223d7faa82c0f10ec42ae1e 616508 net standard openssh-client_10.6p1-1_sh4.deb
 4c3df97573603dd22700f09fc26e84a8 2124740 debug optional openssh-common-dbgsym_10.6p1-1_sh4.deb
 5f3f2896b9567292dfa37da5ca065680 465344 net standard openssh-common_10.6p1-1_sh4.deb
 39597afe194b355e47ec82bb9e3fb582 3624724 debug optional openssh-server-dbgsym_10.6p1-1_sh4.deb
 21b1297b32771e0ad7466a352482dd3f 444776 debian-installer optional openssh-server-udeb_10.6p1-1_sh4.udeb
 514150f96d41d59f6029f1b2ec699612 528744 net optional openssh-server_10.6p1-1_sh4.deb
 f0c7375bc4590df9066a36f0ffe109e7 201160 debug optional openssh-sftp-server-dbgsym_10.6p1-1_sh4.deb
 d34e24737207f9ec24174da1169b7505 66568 net optional openssh-sftp-server_10.6p1-1_sh4.deb
 e3e1af2d945536b8ad79ac3a257853c6 6395648 debug optional openssh-tests-dbgsym_10.6p1-1_sh4.deb
 3f9c50f1620e8bb68ee86017c61c5c24 1166116 net optional openssh-tests_10.6p1-1_sh4.deb
 1cbe293bc2ab0f149d47298ef4e89741 18117 net standard openssh_10.6p1-1_sh4.buildinfo
 f5c0df2967130f7adbdaa5f8b83c0445 17992 debug optional ssh-askpass-gnome-dbgsym_10.6p1-1_sh4.deb
 0b577943b1424989fed4bd4216b464c7 14652 gnome optional ssh-askpass-gnome_10.6p1-1_sh4.deb
 ab52ade415b9ecf4a9899d86237333bb 1188 net optional ssh_10.6p1-1_sh4.deb
Signed-By: Debian buildd autosigning key for sh4-do-02 <buildd_sh4-sh4-do-02@buildd.debian.org>

