OpenSSH 10.5 Drops Five Weeks Early to Fix AI-Discovered Vulnerabilities

Published by

OpenSSH 10.5 has been released just five weeks after 10.4, driven by a surge of vulnerabilities identified by AI, leading to a faster release cycle. The update addresses three significant security flaws, including a critical ssh-agent locking bypass and other bugs, while also introducing new features such as improvements for FIDO key usability and an ssh -Z debugging flag. The accelerated release schedule indicates a shift from OpenSSH's traditional biannual updates, responding to the growing volume of security reports, many of which are confirmed by independent researchers. Users are urged to patch immediately to mitigate active exploitation risks and to review legacy configurations that may have previously overlooked security restrictions



OpenSSH 10.5 Drops Five Weeks Early to Fix AI-Discovered Vulnerabilities

OpenSSH 10.5 drops just five weeks after 10.4, with the team explicitly crediting a surge of AI-discovered vulnerabilities for triggering faster, on-demand release cycles. The update patches three security flaws, including a critical ssh-agent locking bypass, a realloc use-after-free bug in remote forwarding, and a tunnel restriction gap in authorized_keys. New features include FIDO key usability improvements, an ssh -Z debugging flag, and a hard requirement for NIST P-521 ECC support in default builds. Operators should patch immediately to close active exploitation paths and audit legacy PermitTunnel configurations that previously bypassed restrict keywords.

OpenSSH 10.5 Drops Five Weeks Early to Fix AI-Discovered Vulnerabilities @ Linux Compatible