From foo@bar  Tue Sep  1 00:30:02 2026
Format: 1.8
Date: Mon, 31 Aug 2026 23:45:36 +0100
Source: openssh-gssapi
Binary: openssh-client-gssapi openssh-client-gssapi-dbgsym openssh-server-gssapi openssh-server-gssapi-dbgsym
Architecture: alpha
Version: 1:10.5p1-1
Distribution: sid
Urgency: medium
Maintainer: alpha Build Daemon (alpha-sc-02) <alpha-sc-02@alpha-sc-02.buildd.org>
Changed-By: Colin Watson <cjwatson@debian.org>
Description:
 openssh-client-gssapi - secure shell (SSH) client, with GSS-API support
 openssh-server-gssapi - secure shell (SSH) server, with GSS-API key exchange
Closes: 1144192
Changes:
 openssh-gssapi (1:10.5p1-1) unstable; urgency=medium
 .
   * password-auth-no-pam: Run test daemon via systemd.
   * New upstream release (closes: #1144192):
     - CVE-2026-73281: ssh-agent(1): fix an interaction between agent locking
       and the session-bind@openssh.com extension that is used to identify
       forwarded agents. These binding requests were refused when the agent
       was locked, with the result that operations that were intended to be
       limited to local use only could be performed remotely, including the
       ability to add PKCS#11 tokens and make use of keys that had
       destination restrictions applied.
     - CVE-2026-73282: ssh(1): avoid potential realloc use-after-free in the
       client if a remote forwarding is added via the local session
       multiplexing socket while a remote forwarding open request is pending
       with the server.
     - CVE-2026-73283: sshd(8): make the authorized_keys "restrict" keyword
       apply correctly to tunnel forwarding too (which is administratively
       disabled by default).
     - ssh-keygen(1): add ability to set or clear the touch-required and
       verify-required flags on FIDO private keys when resetting a private
       key's passphrase.
     - ssh(1): tweak ordering of certificates tried during pubkey
       authentication to prefer FIDO keys that do not require user presence
       (touch) first, and FIDO keys that require user verification via PIN or
       biometrics last. This effectively tries low-friction authenticators
       before higher friction ones.
     - ssh(1): add a "ssh -Z user@host" mode that prints the keys that will
       be tried for public key authentication in the order that they will be
       used.
     - sshd(8) use setproctitle(3) to identify sshd-session when it's acting
       as a post-authentication monitor.
     - ssh-keyscan(1): make reading the server banner a non-blocking
       operation to prevent a stuck server from blocking a many-host keyscan
       from proceeding.
     - sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the
       packet code as this provides context of the failing peer (address,
       port, user, etc).
     - sshd(8): when signing hostkey proofs for a client UpdateHostKeys
       request, allow each hostkey to perform at most one signature
       operation.
     - ssh-keygen(1): pass back errors from ed25519 key generation, which
       theoretically can fail.
     - sshd(8): move check of public key type against allowed algorithms to
       before parsing of the key sent by the peer. This removes at least some
       key parsing and verification paths from the pre-auth attack surface.
     - ssh-keygen(1): fix double frees (impossible to reach outside of a test
       harness), and also use freezero where possible.
     - sshd(8): fix ChannelTimeout and RekeyLimit not being applied in
       sshd_config Match blocks.
     - sshd(8): in sshd config dump mode, write all directives in mixed case
       for consistency.
     - sshd(8): re-allow PAMServiceName inside a Match block, which was
       incorrectly disabled during a refactoring in openssh-10.4.
Checksums-Sha1:
 969136627b68c8f46db484b2004f6555c9fed276 4174348 openssh-client-gssapi-dbgsym_10.5p1-1_alpha.deb
 3a7f7a47606e74db138ba9d1e189e9b9ba8338ba 880164 openssh-client-gssapi_10.5p1-1_alpha.deb
 377a38ee1740bf307c7aa85e39b17102c729bae0 15398 openssh-gssapi_10.5p1-1_alpha.buildinfo
 24fb777aca6dd03f983c98578f881b7220d73098 3211868 openssh-server-gssapi-dbgsym_10.5p1-1_alpha.deb
 9aab5bd93b283685abb2945f933025fea8b7fe78 783304 openssh-server-gssapi_10.5p1-1_alpha.deb
Checksums-Sha256:
 2d3bcd8f4f8305a502854591f2fdce737744fe053232439245c56b2998388ca7 4174348 openssh-client-gssapi-dbgsym_10.5p1-1_alpha.deb
 91c697d59bf6bf91a2e55a9505854f6211d024a4b10fa06314c2b14540ea0bf0 880164 openssh-client-gssapi_10.5p1-1_alpha.deb
 5d005b464ccd48e6a2c8a13062f21c9bf22c67c9cfc46efcb7b64d15f871d617 15398 openssh-gssapi_10.5p1-1_alpha.buildinfo
 05978773f32dc04b710057f61633d8007fce593e849faf9678c5d279a5e395a0 3211868 openssh-server-gssapi-dbgsym_10.5p1-1_alpha.deb
 477c37fde5075ba4e5f9b795707771eb563d76bcc44cefc5d653123a6fac7741 783304 openssh-server-gssapi_10.5p1-1_alpha.deb
Files:
 dbde2229190acb9c951ac975ec99bbeb 4174348 debug optional openssh-client-gssapi-dbgsym_10.5p1-1_alpha.deb
 a935c3d0ee28a566a8eac77fd1a1beb7 880164 net optional openssh-client-gssapi_10.5p1-1_alpha.deb
 ea98f701c470de4d1af73fbdfde2eb88 15398 net optional openssh-gssapi_10.5p1-1_alpha.buildinfo
 bdfe9ae2e75fa9cacce13b197262d139 3211868 debug optional openssh-server-gssapi-dbgsym_10.5p1-1_alpha.deb
 f8a943a61fd527b79457dd217ec663ab 783304 net optional openssh-server-gssapi_10.5p1-1_alpha.deb
Signed-By: Debian buildd autosigning key for alpha-sc-02 <buildd_alpha-alpha-sc-02@buildd.debian.org>

