OpenSSH 10.6 Released: Post-Quantum Signatures and Compression Side-Channel Fix

Published by

OpenSSH 10.6 has been released, introducing a number of important updates, including the disabling of the LZ77 dictionary coder to mitigate a newly identified compression side-channel attack called "Crossing the Streams." This version also standardizes the hybrid post-quantum signature algorithm ssh-mldsa44-ed25519, requiring users to regenerate keys created with an older experimental version. The release notes highlight an increase in AI-assisted bug reports, prompting the development team to expedite their release cadence for security fixes. Other enhancements include stricter username input validation, improved GSSAPI credential handling, and an upgrade to key stretching parameters, alongside various general improvements and deprecations



OpenSSH 10.6 Released: Post-Quantum Signatures and Compression Side-Channel Fix

OpenSSH 10.6 released as the latest point release in the 10.x series. The update disables the LZ77 dictionary coder to mitigate "Crossing the Streams," the first compression side-channel attack against SSH. It also standardizes the hybrid post-quantum ssh-mldsa44-ed25519 signature algorithm, meaning keys made with the old experimental @openssh.com suffix must be regenerated.

OpenSSH 10.6 Released: Post-Quantum Signatures and Compression Side-Channel Fix @ Linux Compatible