From foo@bar  Tue Sep  1 00:30:02 2026
Format: 1.8
Date: Mon, 31 Aug 2026 23:45:36 +0100
Source: openssh-gssapi
Binary: openssh-client-gssapi openssh-client-gssapi-dbgsym openssh-server-gssapi openssh-server-gssapi-dbgsym
Architecture: hppa
Version: 1:10.5p1-1
Distribution: sid
Urgency: medium
Maintainer: hppa Build Daemon (paladin) <buildd@paladin.parisc-linux.org>
Changed-By: Colin Watson <cjwatson@debian.org>
Description:
 openssh-client-gssapi - secure shell (SSH) client, with GSS-API support
 openssh-server-gssapi - secure shell (SSH) server, with GSS-API key exchange
Closes: 1144192
Changes:
 openssh-gssapi (1:10.5p1-1) unstable; urgency=medium
 .
   * password-auth-no-pam: Run test daemon via systemd.
   * New upstream release (closes: #1144192):
     - CVE-2026-73281: ssh-agent(1): fix an interaction between agent locking
       and the session-bind@openssh.com extension that is used to identify
       forwarded agents. These binding requests were refused when the agent
       was locked, with the result that operations that were intended to be
       limited to local use only could be performed remotely, including the
       ability to add PKCS#11 tokens and make use of keys that had
       destination restrictions applied.
     - CVE-2026-73282: ssh(1): avoid potential realloc use-after-free in the
       client if a remote forwarding is added via the local session
       multiplexing socket while a remote forwarding open request is pending
       with the server.
     - CVE-2026-73283: sshd(8): make the authorized_keys "restrict" keyword
       apply correctly to tunnel forwarding too (which is administratively
       disabled by default).
     - ssh-keygen(1): add ability to set or clear the touch-required and
       verify-required flags on FIDO private keys when resetting a private
       key's passphrase.
     - ssh(1): tweak ordering of certificates tried during pubkey
       authentication to prefer FIDO keys that do not require user presence
       (touch) first, and FIDO keys that require user verification via PIN or
       biometrics last. This effectively tries low-friction authenticators
       before higher friction ones.
     - ssh(1): add a "ssh -Z user@host" mode that prints the keys that will
       be tried for public key authentication in the order that they will be
       used.
     - sshd(8) use setproctitle(3) to identify sshd-session when it's acting
       as a post-authentication monitor.
     - ssh-keyscan(1): make reading the server banner a non-blocking
       operation to prevent a stuck server from blocking a many-host keyscan
       from proceeding.
     - sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the
       packet code as this provides context of the failing peer (address,
       port, user, etc).
     - sshd(8): when signing hostkey proofs for a client UpdateHostKeys
       request, allow each hostkey to perform at most one signature
       operation.
     - ssh-keygen(1): pass back errors from ed25519 key generation, which
       theoretically can fail.
     - sshd(8): move check of public key type against allowed algorithms to
       before parsing of the key sent by the peer. This removes at least some
       key parsing and verification paths from the pre-auth attack surface.
     - ssh-keygen(1): fix double frees (impossible to reach outside of a test
       harness), and also use freezero where possible.
     - sshd(8): fix ChannelTimeout and RekeyLimit not being applied in
       sshd_config Match blocks.
     - sshd(8): in sshd config dump mode, write all directives in mixed case
       for consistency.
     - sshd(8): re-allow PAMServiceName inside a Match block, which was
       incorrectly disabled during a refactoring in openssh-10.4.
Checksums-Sha1:
 d528459256373e349f90a2abfa4ca7f70575d005 3850648 openssh-client-gssapi-dbgsym_10.5p1-1_hppa.deb
 96aa3ae4bdf6fa98d7f26699437a6a108f564073 826464 openssh-client-gssapi_10.5p1-1_hppa.deb
 759f73211592c3c3028f789d1af3dfe0263ab92a 15277 openssh-gssapi_10.5p1-1_hppa.buildinfo
 f8b0dadd445a67a02a1240180bb130dcb7eaa99d 2973484 openssh-server-gssapi-dbgsym_10.5p1-1_hppa.deb
 214d70a2b4c94c3830cade1ee67ac6331342f1f9 740960 openssh-server-gssapi_10.5p1-1_hppa.deb
Checksums-Sha256:
 c42cb2cec24418def7f03338b3ebfbe548310ed3767c5ca61eaf9c67ccd8fbb1 3850648 openssh-client-gssapi-dbgsym_10.5p1-1_hppa.deb
 2123f10ac8c445263451b04b6b27d25471fd3d5be45ee7ba868235ed6691ed8d 826464 openssh-client-gssapi_10.5p1-1_hppa.deb
 5311643e452472dae5e7e94343083ab9700b05ac186b771d86864ddbfee472fc 15277 openssh-gssapi_10.5p1-1_hppa.buildinfo
 4ffae18eea8a01ba0dbe55a5548b46add8ffe114a1b44b92a69b03608e600934 2973484 openssh-server-gssapi-dbgsym_10.5p1-1_hppa.deb
 e809c870f9d31b0020aed0c0e5cfc4652f6ec7b963db5b731ea990610e8bf109 740960 openssh-server-gssapi_10.5p1-1_hppa.deb
Files:
 961f2ae3b2c5e11efe4e5ebc07af6af8 3850648 debug optional openssh-client-gssapi-dbgsym_10.5p1-1_hppa.deb
 e4a3e773358025273210ac372f22d21c 826464 net optional openssh-client-gssapi_10.5p1-1_hppa.deb
 2a5bef0737a9be44eb6c3f38dd8f823c 15277 net optional openssh-gssapi_10.5p1-1_hppa.buildinfo
 b1c9a21ea77efb08fc1d4fd162b55b09 2973484 debug optional openssh-server-gssapi-dbgsym_10.5p1-1_hppa.deb
 0ff42b5d40341a6de09c477927ab5239 740960 net optional openssh-server-gssapi_10.5p1-1_hppa.deb
Signed-By: Debian buildd autosigning key for paladin <buildd_hppa-paladin@buildd.debian.org>

