From foo@bar  Tue Sep  1 01:00:07 2026
Format: 1.8
Date: Mon, 31 Aug 2026 23:45:36 +0100
Source: openssh-gssapi
Binary: openssh-client-gssapi openssh-client-gssapi-dbgsym openssh-server-gssapi openssh-server-gssapi-dbgsym
Architecture: sh4
Version: 1:10.5p1-1
Distribution: sid
Urgency: medium
Maintainer: sh4 Build Daemon (sh4-do-01) <buildd@sh4-do-01.buildd.org>
Changed-By: Colin Watson <cjwatson@debian.org>
Description:
 openssh-client-gssapi - secure shell (SSH) client, with GSS-API support
 openssh-server-gssapi - secure shell (SSH) server, with GSS-API key exchange
Closes: 1144192
Changes:
 openssh-gssapi (1:10.5p1-1) unstable; urgency=medium
 .
   * password-auth-no-pam: Run test daemon via systemd.
   * New upstream release (closes: #1144192):
     - CVE-2026-73281: ssh-agent(1): fix an interaction between agent locking
       and the session-bind@openssh.com extension that is used to identify
       forwarded agents. These binding requests were refused when the agent
       was locked, with the result that operations that were intended to be
       limited to local use only could be performed remotely, including the
       ability to add PKCS#11 tokens and make use of keys that had
       destination restrictions applied.
     - CVE-2026-73282: ssh(1): avoid potential realloc use-after-free in the
       client if a remote forwarding is added via the local session
       multiplexing socket while a remote forwarding open request is pending
       with the server.
     - CVE-2026-73283: sshd(8): make the authorized_keys "restrict" keyword
       apply correctly to tunnel forwarding too (which is administratively
       disabled by default).
     - ssh-keygen(1): add ability to set or clear the touch-required and
       verify-required flags on FIDO private keys when resetting a private
       key's passphrase.
     - ssh(1): tweak ordering of certificates tried during pubkey
       authentication to prefer FIDO keys that do not require user presence
       (touch) first, and FIDO keys that require user verification via PIN or
       biometrics last. This effectively tries low-friction authenticators
       before higher friction ones.
     - ssh(1): add a "ssh -Z user@host" mode that prints the keys that will
       be tried for public key authentication in the order that they will be
       used.
     - sshd(8) use setproctitle(3) to identify sshd-session when it's acting
       as a post-authentication monitor.
     - ssh-keyscan(1): make reading the server banner a non-blocking
       operation to prevent a stuck server from blocking a many-host keyscan
       from proceeding.
     - sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the
       packet code as this provides context of the failing peer (address,
       port, user, etc).
     - sshd(8): when signing hostkey proofs for a client UpdateHostKeys
       request, allow each hostkey to perform at most one signature
       operation.
     - ssh-keygen(1): pass back errors from ed25519 key generation, which
       theoretically can fail.
     - sshd(8): move check of public key type against allowed algorithms to
       before parsing of the key sent by the peer. This removes at least some
       key parsing and verification paths from the pre-auth attack surface.
     - ssh-keygen(1): fix double frees (impossible to reach outside of a test
       harness), and also use freezero where possible.
     - sshd(8): fix ChannelTimeout and RekeyLimit not being applied in
       sshd_config Match blocks.
     - sshd(8): in sshd config dump mode, write all directives in mixed case
       for consistency.
     - sshd(8): re-allow PAMServiceName inside a Match block, which was
       incorrectly disabled during a refactoring in openssh-10.4.
Checksums-Sha1:
 ccce205582e5d2c956c1b464164e7b5c884c3be5 4810436 openssh-client-gssapi-dbgsym_10.5p1-1_sh4.deb
 c425375e400743e75484bde8863e3e0aa3569e74 811580 openssh-client-gssapi_10.5p1-1_sh4.deb
 8a87708d9bbd35455502bb86efb54d44ada47300 15371 openssh-gssapi_10.5p1-1_sh4.buildinfo
 786a9a67c85bcea7bf726d0aef554c4afbedcfa3 3708240 openssh-server-gssapi-dbgsym_10.5p1-1_sh4.deb
 bb8fbaf040d844aa7c7fe7eb785610b3671a72ce 725616 openssh-server-gssapi_10.5p1-1_sh4.deb
Checksums-Sha256:
 af6d9bcb5c2854a483900842eb904744733cf9f9a99c5239e33d953f332dc703 4810436 openssh-client-gssapi-dbgsym_10.5p1-1_sh4.deb
 5ff2ae57e938a40fbfea51b84b8cd93ab8f13a5d46cc663ab8e9ece5abc3a453 811580 openssh-client-gssapi_10.5p1-1_sh4.deb
 8aa41fb8a04ac2ef47847de0137c1dc78b3921a3a3982df3efa45dc519fafe3c 15371 openssh-gssapi_10.5p1-1_sh4.buildinfo
 e87a9de22fbe8e773aeb09bcc953a6228b3b35cbfe0b9cc269f33d5e19d09447 3708240 openssh-server-gssapi-dbgsym_10.5p1-1_sh4.deb
 4b5a68cb49f4012c3d745c5646624a61f5fcc6187724d060c80a2d9f95fa41a2 725616 openssh-server-gssapi_10.5p1-1_sh4.deb
Files:
 c3d5a3f1aba0641a0b577665bc30e897 4810436 debug optional openssh-client-gssapi-dbgsym_10.5p1-1_sh4.deb
 8abf33ddb4707c997f8dadab70aac36d 811580 net optional openssh-client-gssapi_10.5p1-1_sh4.deb
 b2db9a10f8aacbed7c5b734e226ddde3 15371 net optional openssh-gssapi_10.5p1-1_sh4.buildinfo
 da8c5fb6dca3191bbc082159c44c2e5b 3708240 debug optional openssh-server-gssapi-dbgsym_10.5p1-1_sh4.deb
 b5c5dc44875b0e14b9a4c41a8aa7984a 725616 net optional openssh-server-gssapi_10.5p1-1_sh4.deb
Signed-By: Debian buildd autosigning key for sh4-do-01 <buildd_sh4-sh4-do-01@buildd.debian.org>

