[openssh-commits] [openssh] 01/06: upstream: Disable LZ77 dictionary coder to avoid a potential
git+noreply at mindrot.org
git+noreply at mindrot.org
Thu Oct 1 08:50:58 AEST 2026
This is an automated email from the git hooks/post-receive script.
djm pushed a commit to branch master
in repository openssh.
commit 1d5340fce24526719e32aebc4c721fc228182ace
Author: job at openbsd.org <job at openbsd.org>
AuthorDate: Tue Sep 22 04:38:09 2026 +0000
upstream: Disable LZ77 dictionary coder to avoid a potential
side-channel leak
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
A chosen-plaintext attack method exists which makes use of
dictionary-based compression to recover secrets from one channel by
interacting with the SSH session's shared compression dictionary through
another channel.
Attacker-controlled input can recognizably reflect into the total length
of transmitted ciphertexts by virtue of LZ77 replacing repeated strings
with back-references into the SSH session's encoder search buffer,
which is shared across all channels. For this reason, the documentation
already recommended against enabling compression for connections that
share trusted and untrusted traffic.
As an extra precaution, use only Huffman coding when compressing
plaintexts, as this algorithm does not use a dictionary. But, this
results in a reduction of compression effectiveness.
Inspired by "Crossing the Streams: SSH Plaintext Recovery via a Common
Compression Context in Multiplexed Channels." by Fabian Bäumer and
Marcus Brinkmann, preprint https://arxiv.org/abs/2609.07709 (2026)
OK djm@ dtucker@
OpenBSD-Commit-ID: 839e5e53ad76786d0e90bed530304e4e13acbba0
---
packet.c | 17 ++++++++---------
1 file changed, 8 insertions(+), 9 deletions(-)
diff --git a/packet.c b/packet.c
index 09343197e..38a8c31bd 100644
--- a/packet.c
+++ b/packet.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: packet.c,v 1.344 2026/09/22 00:24:47 dtucker Exp $ */
+/* $OpenBSD: packet.c,v 1.345 2026/09/22 04:38:09 job Exp $ */
/*
* Author: Tatu Ylonen <ylo at cs.hut.fi>
* Copyright (c) 1995 Tatu Ylonen <ylo at cs.hut.fi>, Espoo, Finland
@@ -805,14 +805,13 @@ ssh_packet_init_compression(struct ssh *ssh)
#ifdef WITH_ZLIB
static int
-start_compression_out(struct ssh *ssh, int level)
+start_compression_out(struct ssh *ssh)
{
- if (level < 1 || level > 9)
- return SSH_ERR_INVALID_ARGUMENT;
- debug("Enabling compression at level %d.", level);
+ debug("Enabling compression.");
if (ssh->state->compression_out_started == 1)
deflateEnd(&ssh->state->compression_out_stream);
- switch (deflateInit(&ssh->state->compression_out_stream, level)) {
+ switch (deflateInit2(&ssh->state->compression_out_stream,
+ Z_BEST_SPEED, Z_DEFLATED, 15, 8, Z_HUFFMAN_ONLY)) {
case Z_OK:
ssh->state->compression_out_started = 1;
break;
@@ -938,7 +937,7 @@ uncompress_buffer(struct ssh *ssh, struct sshbuf *in, struct sshbuf *out)
#else /* WITH_ZLIB */
static int
-start_compression_out(struct ssh *ssh, int level)
+start_compression_out(struct ssh *ssh)
{
return SSH_ERR_INTERNAL_ERROR;
}
@@ -1044,7 +1043,7 @@ ssh_set_newkeys(struct ssh *ssh, int mode)
if ((r = ssh_packet_init_compression(ssh)) < 0)
return r;
if (mode == MODE_OUT) {
- if ((r = start_compression_out(ssh, 6)) != 0)
+ if ((r = start_compression_out(ssh)) != 0)
return r;
} else {
if ((r = start_compression_in(ssh)) != 0)
@@ -1189,7 +1188,7 @@ ssh_packet_enable_delayed_compress(struct ssh *ssh)
if ((r = ssh_packet_init_compression(ssh)) != 0)
return r;
if (mode == MODE_OUT) {
- if ((r = start_compression_out(ssh, 6)) != 0)
+ if ((r = start_compression_out(ssh)) != 0)
return r;
} else {
if ((r = start_compression_in(ssh)) != 0)
--
To stop receiving notification emails like this one, please contact
djm at mindrot.org.
More information about the openssh-commits
mailing list