[openssh-commits] [openssh] branch master updated: upstream: Further restrict the characters allowed in a command-line

git+noreply at mindrot.org git+noreply at mindrot.org
Mon Oct 5 17:19:50 AEDT 2026


This is an automated email from the git hooks/post-receive script.

djm pushed a commit to branch master
in repository openssh.

The following commit(s) were added to refs/heads/master by this push:
     new 0c4c9a7b3 upstream: Further restrict the characters allowed in a command-line
0c4c9a7b3 is described below

commit 0c4c9a7b320bd7ff61c4a2dc345cb2e27e9663b2
Author: dtucker at openbsd.org <dtucker at openbsd.org>
AuthorDate: Mon Oct 5 06:03:40 2026 +0000

    upstream: Further restrict the characters allowed in a command-line
    
    supplied user name, disallowing '$' and '\'. Reported by SecBuddyF KeenLab
    Tencent (CodeBuddy Security).
    
    OpenBSD-Commit-ID: 13671c178f492af63b5c1296f284818c7809ed9a
---
 readconf.c | 7 ++-----
 1 file changed, 2 insertions(+), 5 deletions(-)

diff --git a/readconf.c b/readconf.c
index 4def155f6..9b557dedf 100644
--- a/readconf.c
+++ b/readconf.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: readconf.c,v 1.418 2026/10/03 00:46:29 djm Exp $ */
+/* $OpenBSD: readconf.c,v 1.419 2026/10/05 06:03:40 dtucker Exp $ */
 /*
  * Author: Tatu Ylonen <ylo at cs.hut.fi>
  * Copyright (c) 1995 Tatu Ylonen <ylo at cs.hut.fi>, Espoo, Finland
@@ -3461,14 +3461,11 @@ ssh_valid_ruser(const char *s)
 	for (i = 0; s[i] != 0; i++) {
 		if (iscntrl((u_char)s[i]))
 			return 0;
-		if (strchr("'`\";&<>|(){}", s[i]) != NULL)
+		if (strchr("'`\";&<>|(){}$\\", s[i]) != NULL)
 			return 0;
 		/* Disallow '-' after whitespace */
 		if (isspace((u_char)s[i]) && s[i + 1] == '-')
 			return 0;
-		/* Disallow \ in last position */
-		if (s[i] == '\\' && s[i + 1] == '\0')
-			return 0;
 	}
 	return 1;
 }

-- 
To stop receiving notification emails like this one, please contact
djm at mindrot.org.


More information about the openssh-commits mailing list