[openssh-commits] [openssh] branch master updated (ccc26c76c -> e27b6cc2e)
git+noreply at mindrot.org
git+noreply at mindrot.org
Thu Oct 1 08:50:57 AEST 2026
This is an automated email from the git hooks/post-receive script.
djm pushed a change to branch master
in repository openssh.
from ccc26c76c upstream: check ssh's handling of stale multiplexing sockets From Jens
new 1d5340fce upstream: Disable LZ77 dictionary coder to avoid a potential
new d4ed84e4c upstream: ssh-agent: fix socket cleanup for -a option (no pathspec)
new ed67a2451 upstream: ssh-agent: no unlink(2) on empty filename
new e0f85d83c upstream: Check that compressed payloads don't inflate beyond the
new fc6ca48d1 upstream: backout
new e27b6cc2e upstream: Disallow nul byte in received scp -O filename. Not
The 6 revisions listed above as "new" are entirely new to this
repository and will be described in separate emails. The revisions
listed as "add" were already present in the repository and have only
been added to this reference.
Detailed log of new commits:
commit e27b6cc2e6e8ba03808f7078740e5ba800515d4d
Author: dtucker at openbsd.org <dtucker at openbsd.org>
Date: Sun Sep 27 22:39:40 2026 +0000
upstream: Disallow nul byte in received scp -O filename. Not
reachable in normal operation since a nul would cause a filename mismatch,
but potentially possible if being used an unusual configuration such as a
custom filter.
Reported by Chua Wei Xun <weixun.chua at e-cq.net>, ok djm@
OpenBSD-Commit-ID: 1fb35933acdc11dd66bdba780bd9e100bda69079
commit fc6ca48d15419f23a6a2ea3c0115b8f32c3dcc69
Author: djm at openbsd.org <djm at openbsd.org>
Date: Wed Sep 23 21:42:39 2026 +0000
upstream: backout
> avoid race between multiple processes attempting to
>
> establish multiplexing control socket by moving socket creation earlier in
> ssh(1)'s life. Patch from Jens Rosenboom via bz3971
It caused problems with ControlPersist sessions.
Reported by semarie@ job@
OpenBSD-Commit-ID: b78a34d605c47cb145e16a3bba295caa0e9db680
commit e0f85d83ccc15b1b218fa8a000fc29a2e3d2defd
Author: job at openbsd.org <job at openbsd.org>
Date: Tue Sep 22 22:51:43 2026 +0000
upstream: Check that compressed payloads don't inflate beyond the
maximum payload length
From a report by Oleh Konko (1seal)
OK djm@
OpenBSD-Commit-ID: a0d3e7aa432777c28bfe23e5447ac117d6c151d9
commit ed67a24515aa65fded1e10426198a4251f836338
Author: djm at openbsd.org <djm at openbsd.org>
Date: Tue Sep 22 22:30:27 2026 +0000
upstream: ssh-agent: no unlink(2) on empty filename
from markus@ ok me
OpenBSD-Commit-ID: 7a517a64389e389e5d23f781d1762c2b6aaffe98
commit d4ed84e4cb15305d763a3acb16d8cf8693c65840
Author: djm at openbsd.org <djm at openbsd.org>
Date: Tue Sep 22 22:29:27 2026 +0000
upstream: ssh-agent: fix socket cleanup for -a option (no pathspec)
from markus@ ok me
OpenBSD-Commit-ID: 3194c1ed609eaa05932b9f6036ace7561e140627
commit 1d5340fce24526719e32aebc4c721fc228182ace
Author: job at openbsd.org <job at openbsd.org>
Date: Tue Sep 22 04:38:09 2026 +0000
upstream: Disable LZ77 dictionary coder to avoid a potential
side-channel leak
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
A chosen-plaintext attack method exists which makes use of
dictionary-based compression to recover secrets from one channel by
interacting with the SSH session's shared compression dictionary through
another channel.
Attacker-controlled input can recognizably reflect into the total length
of transmitted ciphertexts by virtue of LZ77 replacing repeated strings
with back-references into the SSH session's encoder search buffer,
which is shared across all channels. For this reason, the documentation
already recommended against enabling compression for connections that
share trusted and untrusted traffic.
As an extra precaution, use only Huffman coding when compressing
plaintexts, as this algorithm does not use a dictionary. But, this
results in a reduction of compression effectiveness.
Inspired by "Crossing the Streams: SSH Plaintext Recovery via a Common
Compression Context in Multiplexed Channels." by Fabian Bäumer and
Marcus Brinkmann, preprint https://arxiv.org/abs/2609.07709 (2026)
OK djm@ dtucker@
OpenBSD-Commit-ID: 839e5e53ad76786d0e90bed530304e4e13acbba0
Summary of changes:
clientloop.h | 3 +--
misc-agent.c | 6 +++--
mux.c | 73 ++++++++++++++++++++++++++++++------------------------------
packet.c | 19 ++++++++--------
scp.c | 4 +++-
ssh-agent.c | 5 +++--
ssh.c | 8 ++-----
7 files changed, 59 insertions(+), 59 deletions(-)
--
To stop receiving notification emails like this one, please contact
djm at mindrot.org.
More information about the openssh-commits
mailing list