OpenSSH 10.6 Introduces Experimental Post-Quantum Signatures, Addresses Multiple Security Flaws
OpenSSH 10.6 has been released, featuring experimental support for a post-quantum signature algorithm and patching numerous security vulnerabilities, many identified with AI assistance.

The OpenSSH development team has rolled out version 10.6, signaling a commitment to more frequent releases to expedite the delivery of critical bug fixes to users. This latest iteration introduces experimental support for a post-quantum signature algorithm, a significant step towards future-proofing secure communication against emerging cryptographic threats.
The release also addresses a substantial number of security reports, with the maintainers noting that a significant portion were discovered with the aid of artificial intelligence models or through AI-assisted research. This trend highlights the growing role of AI in both vulnerability discovery and potentially, exploitation, prompting the team to emphasize that adversaries are likely to find similar flaws.
In a notable change affecting network performance, both the ssh client and server now disable the LZ77 dictionary coder, diminishing the effectiveness of the Compression option. This decision stems from a discovered attack vector where control over one channel could allow an attacker to recover secrets from another by exploiting shared compression dictionaries. The OpenSSH team now recommends application-level compression as a more robust and secure alternative.
Security has also been tightened around username handling. The ssh client will now refuse command-line usernames containing a dollar sign ($) or backslash (\). This measure aims to prevent potential injection attacks through mechanisms like ProxyCommand or Match exec when dealing with untrusted username sources, though the maintainers caution that such mitigations cannot be absolute.
Several other security enhancements and fixes are included in version 10.6. For instance, sshd now ensures that GSSAPI credentials are only stored after successful authentication, preventing potential exposure from prior failed attempts. The sftp subsystem has also received stricter validation for server-returned paths, closing a loophole that could allow a server to redirect recursive copies outside their intended directories.
Further refinements include corrections to ssh-keygen's handling of Daylight Saving Time, which could previously lead to certificate expiry times being off by up to an hour. Additionally, specific platforms like QNX 6 and SCO OpenServer 5, as well as builds with disabled file descriptor passing, will now have GatewayPorts and StreamLocalForwarding disabled post-authentication due to root persistence issues. Support for these platforms may be removed in future releases if alternative solutions are not found.
The introduction of the hybrid post-quantum signature algorithm, ssh-mldsa44-ed25519, marks a forward-looking aspect of this release. Users who previously generated experimental keys with older support for post-quantum cryptography will need to regenerate or remove them to ensure compatibility and security with this new cryptographic approach.
This release underscores OpenSSH's ongoing efforts to maintain robust security and adapt to evolving cryptographic landscapes, while also acknowledging the increasing influence of AI in the cybersecurity domain.