[openssh-commits] [openssh] branch master updated (94bf1154b -> f878d7ccc)
git+noreply at mindrot.org
git+noreply at mindrot.org
Tue Dec 16 20:41:44 AEDT 2025
This is an automated email from the git hooks/post-receive script.
dtucker pushed a change to branch master
in repository openssh.
from 94bf1154b upstream: add a GssDelegateCreds option for the server, controlling
new 49480f193 upstream: Add 'invaliduser' penalty to PerSourcePenalties, which is
new f878d7ccc upstream: Plug leak in ssh_digest_memory on error path.
The 2 revisions listed above as "new" are entirely new to this
repository and will be described in separate emails. The revisions
listed as "add" were already present in the repository and have only
been added to this reference.
Detailed log of new commits:
commit f878d7ccc25b02a39e6766f5dd405d5de6fb106c
Author: dtucker at openbsd.org <dtucker at openbsd.org>
Date: Tue Dec 16 08:36:43 2025 +0000
upstream: Plug leak in ssh_digest_memory on error path.
Bonehead mistake spotted by otto@, ok djm@
OpenBSD-Commit-ID: 4ad67ac402e0b4c013f4f4e386d22b88969a5dd7
commit 49480f1934f8cf994afa646d4bcbd22ac08bb6af
Author: dtucker at openbsd.org <dtucker at openbsd.org>
Date: Tue Dec 16 08:32:50 2025 +0000
upstream: Add 'invaliduser' penalty to PerSourcePenalties, which is
applied to login attempts for usernames that do not match real accounts.
Defaults to 5s to match 'authfail' but allows administrators to block such
sources for longer if desired. with & ok djm@
OpenBSD-Commit-ID: bb62797bcf2adceb96f608ce86d0bb042aff5834
Summary of changes:
digest-libc.c | 7 ++++---
monitor.c | 18 ++++++++++++++++--
monitor.h | 5 ++++-
servconf.c | 9 ++++++++-
servconf.h | 3 ++-
srclimit.c | 6 +++++-
srclimit.h | 2 ++
sshd-session.c | 8 ++++----
sshd.c | 8 +++++++-
sshd_config.5 | 7 +++++--
10 files changed, 57 insertions(+), 16 deletions(-)
--
To stop receiving notification emails like this one, please contact
djm at mindrot.org.
More information about the openssh-commits
mailing list