[openssh-commits] [openssh] 01/06: upstream: Disable LZ77 dictionary coder to avoid a potential

git+noreply at mindrot.org git+noreply at mindrot.org
Thu Oct 1 08:50:58 AEST 2026


This is an automated email from the git hooks/post-receive script.

djm pushed a commit to branch master
in repository openssh.

commit 1d5340fce24526719e32aebc4c721fc228182ace
Author: job at openbsd.org <job at openbsd.org>
AuthorDate: Tue Sep 22 04:38:09 2026 +0000

    upstream: Disable LZ77 dictionary coder to avoid a potential
    
    side-channel leak
    MIME-Version: 1.0
    Content-Type: text/plain; charset=UTF-8
    Content-Transfer-Encoding: 8bit
    
    A chosen-plaintext attack method exists which makes use of
    dictionary-based compression to recover secrets from one channel by
    interacting with the SSH session's shared compression dictionary through
    another channel.
    
    Attacker-controlled input can recognizably reflect into the total length
    of transmitted ciphertexts by virtue of LZ77 replacing repeated strings
    with back-references into the SSH session's encoder search buffer,
    which is shared across all channels. For this reason, the documentation
    already recommended against enabling compression for connections that
    share trusted and untrusted traffic.
    
    As an extra precaution, use only Huffman coding when compressing
    plaintexts, as this algorithm does not use a dictionary. But, this
    results in a reduction of compression effectiveness.
    
    Inspired by "Crossing the Streams: SSH Plaintext Recovery via a Common
    Compression Context in Multiplexed Channels." by Fabian Bäumer and
    Marcus Brinkmann, preprint https://arxiv.org/abs/2609.07709 (2026)
    
    OK djm@ dtucker@
    
    OpenBSD-Commit-ID: 839e5e53ad76786d0e90bed530304e4e13acbba0
---
 packet.c | 17 ++++++++---------
 1 file changed, 8 insertions(+), 9 deletions(-)

diff --git a/packet.c b/packet.c
index 09343197e..38a8c31bd 100644
--- a/packet.c
+++ b/packet.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: packet.c,v 1.344 2026/09/22 00:24:47 dtucker Exp $ */
+/* $OpenBSD: packet.c,v 1.345 2026/09/22 04:38:09 job Exp $ */
 /*
  * Author: Tatu Ylonen <ylo at cs.hut.fi>
  * Copyright (c) 1995 Tatu Ylonen <ylo at cs.hut.fi>, Espoo, Finland
@@ -805,14 +805,13 @@ ssh_packet_init_compression(struct ssh *ssh)
 
 #ifdef WITH_ZLIB
 static int
-start_compression_out(struct ssh *ssh, int level)
+start_compression_out(struct ssh *ssh)
 {
-	if (level < 1 || level > 9)
-		return SSH_ERR_INVALID_ARGUMENT;
-	debug("Enabling compression at level %d.", level);
+	debug("Enabling compression.");
 	if (ssh->state->compression_out_started == 1)
 		deflateEnd(&ssh->state->compression_out_stream);
-	switch (deflateInit(&ssh->state->compression_out_stream, level)) {
+	switch (deflateInit2(&ssh->state->compression_out_stream,
+	    Z_BEST_SPEED, Z_DEFLATED, 15, 8, Z_HUFFMAN_ONLY)) {
 	case Z_OK:
 		ssh->state->compression_out_started = 1;
 		break;
@@ -938,7 +937,7 @@ uncompress_buffer(struct ssh *ssh, struct sshbuf *in, struct sshbuf *out)
 #else	/* WITH_ZLIB */
 
 static int
-start_compression_out(struct ssh *ssh, int level)
+start_compression_out(struct ssh *ssh)
 {
 	return SSH_ERR_INTERNAL_ERROR;
 }
@@ -1044,7 +1043,7 @@ ssh_set_newkeys(struct ssh *ssh, int mode)
 		if ((r = ssh_packet_init_compression(ssh)) < 0)
 			return r;
 		if (mode == MODE_OUT) {
-			if ((r = start_compression_out(ssh, 6)) != 0)
+			if ((r = start_compression_out(ssh)) != 0)
 				return r;
 		} else {
 			if ((r = start_compression_in(ssh)) != 0)
@@ -1189,7 +1188,7 @@ ssh_packet_enable_delayed_compress(struct ssh *ssh)
 			if ((r = ssh_packet_init_compression(ssh)) != 0)
 				return r;
 			if (mode == MODE_OUT) {
-				if ((r = start_compression_out(ssh, 6)) != 0)
+				if ((r = start_compression_out(ssh)) != 0)
 					return r;
 			} else {
 				if ((r = start_compression_in(ssh)) != 0)

-- 
To stop receiving notification emails like this one, please contact
djm at mindrot.org.


More information about the openssh-commits mailing list