openssh (1:10.4p1-1)
[PTS] [DDPO]
COMMITS: VCS has seen 1 commit since the debian/1%10.4p1-1 tag
- Git: https://salsa.debian.org/ssh-team/openssh.git
-
- Branch: master
- Path: debian/changelog
- Repo size: 5722112
- Browser: https://salsa.debian.org/ssh-team/openssh
- Last scan: 2026-07-08 13:57:11+00
- Next scan: 2026-07-17 03:05:00+00
- Merge requests: 7
- CI pipeline status: success
- Debian changelog in Git:
openssh (1:10.4p1-1) unstable; urgency=medium
[ Sven Joachim ]
* Make doc symlinks relative on upgrade from 1:10.3p1-5 (closes:
#1141420).
[ Colin Watson ]
* New upstream release:
- CVE-2026-59995: sftp(1): when downloading files on the command-line
using "sftp host:/path .", a malicious server could cause the file to
be downloaded to an unexpected location. This issue was identified by
the Swival Security Scanner.
- CVE-2026-59996: scp(1): when copying files between two remote
destinations, do not allow a malicious server to write files to the
parent directory of the intended target directory. This issue was
identified by the Swival Security Scanner.
- CVE-2026-59997: sshd(8): when using the "internal-sftp" SFTP server
implementation (this is not the default), long command lines were
previously truncated silently after the 9th argument. If a
security-relevant option was in the 10th or later position, it would
be discarded. Reported by Steve Caffrey.
- CVE-2026-59998: sshd(8): add a documentation note to mention that the
GSSAPIStrictAcceptorCheck option is ineffective when the server is
joined to a Windows Active Directory. Reported by Yarin Aharoni of
Safebreach.
- CVE-2026-59999: sshd(8): DisableForwarding=yes didn't override
PermitTunnel=yes as it was documented to do. Note that PermitTunnel is
not enabled by default. Reported independently by Huzaifa Sidhpurwala
of Redhat and Marko Jevtic.
- CVE-2026-60000: sshd(8): avoid a potential pre-authentication denial
of service when GSSAPIAuthentication was enabled (this feature is off
by default). This was not mitigated by MaxAuthTries, but would be
penalised by PerSourcePenalties. This was reported by Manfred Kaiser
of the milCERT AT (Austrian Ministry of Defence).
- CVE-2026-60001: sshd(8): fix a number of cases where the minimum
authentication delay was not being enforced. Reported by the Orange
Cyberdefense Vulnerability Team.
- CVE-2026-60002: ssh(1): fix a possible client-side use-after-free if
the server changes its host key during a key reexchange. This was
reported by Zhenpeng (Leo) Lin of Depthfirst.
- All: add experimental support for a composite post-quantum signature
scheme that combines ML-DSA 44 and Ed25519 as specified in
draft-miller-sshm-mldsa44-ed25519-composite-sigs. This scheme is not
enabled by default. To use it, you'll need to add it to
HostKeyAlgorithms, PubkeyAcceptedAlgorithms, etc. Keys may be
generated using "ssh-keygen -t mldsa44-ed25519".
- ssh(1), sshd(8): replace the wildcard pattern matcher with an
implementation based on an NFA. This avoids exponential worst-case
behaviour for the old implementation.
- ssh-agent(1): fix incorrect reply to "query" SSH_AGENTC_EXTENSION
requests.
- sshd(8): avoid sending observably different messages for valid vs
invalid users in GSSAPIAuthentication (disabled by default).
- ssh(1), sshd(8): fix several bugs that incorrectly classified bulk
traffic as interactive.
- ssh-keygen(1), ssh-add(1): skip unsupported key types when downloading
resident keys from a FIDO token. Previously, downloads would abort
when one was encountered.
- ssh(1): fix a potential use-after-free on an error path if
cipher_init() fails.
- sshd(8): perform stricter encoding and validation of transport state
passed between sshd privilege separation subprocesses. This somewhat
further hardens the server against attacks on sshd-auth or
sshd-session subprocesses.
- ssh-agent(1): avoid possible runtime denial of service by enforcing
some limits on the length of usernames in key use constraints.
- sftp(1): fix two separate one-byte out-of-bounds reads, in
SSH2_FXP_REALPATH and batch command processing.
- sftp-server(8): disallow use of the copy-data extension to read and
write to the same inode simultaneously.
- ssh(1), sshd(8): avoid strlen(NULL) crash if an X11 channel was
created before the x11-req SSH_MSG_CHANNEL_REQUEST was sent.
- sftp(1), scp(1): avoid a situation where sftp_download() could get
stuck in a loop if a broken server repeatedly returned zero length
while reading a file.
- ssh(1): avoid leaking DNS0x20 case-randomised names into names
canonicalised using CanonicalizePermittedCNAMEs.
- sftp-server(8): avoid truncation of pathnames passed to lstat() during
SSH_FXP_REALPATH handling on systems where PATH_MAX is not the actual
max.
- ssh(1), sshd(8): correct arming of poll(2) event masks for some
socket-type channels.
- sshd(8): major refactor of sshd_config parsing and management code, to
allow for more exact serialisation/deserialisation across privilege
separation boundaries.
- ssh-add(1): open connection to the agent only after getopt()
processing has completed, to give options like "-v" a chance to
display debug information about this operation.
- sshd(8): differentiate between execution failures and a subsystem that
was not found when logging why a subsystem failed to start.
- All: use safer idioms for timegm(3) and mktime(3) error detection.
- ssh(1), sshd(8): avoid accepting invalid cipher or MAC lists in config
files or command-line arguments. This could cause runtime failures
later.
- ssh(1): fix NULL deref crash during pubkey auth when using a PEM style
private key with no corresponding .pub key adjacent to it (closes:
#1134814).
- sshd(8): don't print an error message when trying to load a host
private key when PKCS#11 keys are in use, as these don't need the
private half on the filesystem.
- All: don't use deprecated ERR_load_crypto_strings().
- ssh(1): properly report errors during configuration default setting.
- ssh(1): use correct directive name (Match instead of Host) in error
message.
- sftp(1): fix "ls -ln" which was not correctly showing numeric UID/GIDs
but rather user and group names.
- sshd(8): avoid possible NULL dereference if an allocation fails during
config parsing.
- All: fix ineffective guards against loading overly large public keys
in several places.
- sftp(1): ensure file descriptors used by sftp to communicate to its
ssh(1) subprocess don't leak into executed subprocesses (e.g. via
"!").
- Sync fmt_scaled.c with OpenBSD upstream, picking up an exactness fix
for large exponents.
- sshd(8): remove duplicate sandbox entry for clock_gettime64.
- Sync getrrsetbyname.c with OpenBSD upstream, picking up robustness
fixes.
- Fix a number of memory leaks on error paths in the portability code.
- Revise the README.privsep documentation to reflect sshd's recent
switch to a multi-binary model.
-- Colin Watson <cjwatson@debian.org> Mon, 06 Jul 2026 19:11:28 +0100
- This branch is 1 commit ahead of tag debian/1%10.4p1-1
- Git log:
commit fc40e849b404ed15b9aee82f034f5cffa863e529
Author: Colin Watson <cjwatson@debian.org>
Date: Wed Jul 8 14:32:16 2026 +0100
Retroactively mention several CVEs in changelog