HeadlinesBriefing HeadlinesBriefing.com

OpenSSH 10.6 Release Notes and Security Updates

Hacker News •
×

OpenSSH 10.6 was released on 2026-10-06, available from the mirrors listed at openssh.com. It is a 100% complete SSH protocol 2.0 implementation with sftp client and server support.

The OpenSSH team has received many security bug reports, often from AI models. While many lack security impact in realistic threat models, the team welcomes them, especially with human triage and proposed fixes. Some AI-identified bugs are later independently found by other researchers, suggesting adversaries could discover them too. Therefore, the team will make more frequent releases to deliver bugfixes faster.

This release includes several security fixes. sftp(1) now more strictly validates server-returned paths to prevent recursive copy operations from writing outside the target directory. sshd(8) with GSSAPIAuthentication only stores credentials after successful authentication, avoiding persistence from failed attempts.

Future deprecations include scp(1)'s -R flag for remote-to-remote copy, which poses security risks and is fragile. Support for platforms lacking file descriptor passing and requiring root for PTY allocation (e.g., SCO Open Server 5, QNX 6) will be removed. Potentially-incompatible changes include stricter username checks and disabled GatewayPorts on affected platforms.

Source: Hacker News · Summarized by HeadlinesBriefing