AI NewsInfrastructureAnnouncement
OpenSSH 10.6 turns off shared compression and tightens usernames
OpenSSH 10.6 disables the LZ77 part of its SSH compression after researchers used Claude Code to prove the shared dictionary leaks plaintext, and rejects dollar and backslash in command-line usernames so a shell cannot interpret them.
Why it mattersAn automated job that compressed large bulk transfers over SSH, or built a user string from outside input, has two things to change before upgrading, or the upgrade will break the job.
A nightly job that moves compressed data over SSH, or an ssh command built from a variable the caller did not fully trust, has two things to fix before the next upgrade.
OpenSSH 10.6 shipped with two changes the maintainers knew would break things. The release disables the LZ77 part of SSH compression in ssh and sshd, and rejects dollar sign and backslash in command-line usernames. Both landed after researchers used AI models to find or prove the flaws.
Compression context leaks plaintext
SSH can carry an interactive shell, port forwarding and a dynamic SOCKS proxy over one encrypted connection. When compression is on, those channels share one compression state. Ruhr University Bochum researchers Fabian Bäumer and Marcus Brinkmann showed in their paper "Crossing the Streams" that an attacker who can feed chosen plaintext into one channel and watch the resulting encrypted traffic can use the compression to recover secrets moving through another channel in the same session.
The researchers built the proofs of concept with Claude Code. The attack sits in the same family as CRIME and BREACH against HTTP over TLS, but needs a specific setup: the attacker-controlled traffic and the secret must share one multiplexed SSH session. In their lowest-noise tests, they recovered an eight-character secret from a 26-character alphabet in a median of 276 guesses across 100 trials. In their noisier browser-based scenario, the figure was about 27,600.
OpenSSH's fix removes the shared dictionary. The LZ77 part of Deflate is off, Huffman coding stays. OpenSSH recommends handling compression at the application layer instead. Interactive sessions probably will not notice. Automated jobs moving large amounts of compressible data over constrained connections could, and may have to move compression out of SSH and into the application after upgrading. Compression is off by default in OpenSSH, so a site that never turned it on is unaffected.
Shell metacharacters in usernames
The second change targets commands built from outside input. An internal tool, CI job or agent might run ssh "$INPUT_USER@host", and that username can later sit inside ProxyCommand, Match exec or another command the shell interprets, where characters like $ and \ become shell syntax instead of part of the username. Version 10.3 had tightened this once already, when command-line usernames were checked for metacharacters too late.
With 10.6, $ and \ are rejected in usernames passed on the command line. The restriction does not apply when the username is set with the User directive in an SSH configuration file, so legitimate accounts containing either character still work. Scripts and agent tooling that pass those usernames directly must change.
Other things to notice before upgrading
Two more items could break automated workflows. The hybrid post-quantum ssh-mldsa44-ed25519 signature algorithm loses its experimental @openssh.com suffix, so keys created with the earlier version need to be regenerated. The release also begins phasing out scp -R for remote-to-remote copies; it still works and now prints a warning.
The release also credits Chris Rohlf, working with Claude and Anthropic Research, with finding two other bugs. OpenSSH said adversaries who do not report their findings "are likely to be able to discover these bugs too", and that the project plans to ship fixes more often than its usual schedule.
Source
This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.
Get AI News in your inbox
New developer tools, model and agent releases, and how teams are actually using them to release software. Short, and only when there is something worth reading.
