[openssh-commits] [openssh] branch master updated: upstream: Further restrict the characters allowed in a command-line
git+noreply at mindrot.org
git+noreply at mindrot.org
Mon Oct 5 17:19:50 AEDT 2026
This is an automated email from the git hooks/post-receive script.
djm pushed a commit to branch master
in repository openssh.
The following commit(s) were added to refs/heads/master by this push:
new 0c4c9a7b3 upstream: Further restrict the characters allowed in a command-line
0c4c9a7b3 is described below
commit 0c4c9a7b320bd7ff61c4a2dc345cb2e27e9663b2
Author: dtucker at openbsd.org <dtucker at openbsd.org>
AuthorDate: Mon Oct 5 06:03:40 2026 +0000
upstream: Further restrict the characters allowed in a command-line
supplied user name, disallowing '$' and '\'. Reported by SecBuddyF KeenLab
Tencent (CodeBuddy Security).
OpenBSD-Commit-ID: 13671c178f492af63b5c1296f284818c7809ed9a
---
readconf.c | 7 ++-----
1 file changed, 2 insertions(+), 5 deletions(-)
diff --git a/readconf.c b/readconf.c
index 4def155f6..9b557dedf 100644
--- a/readconf.c
+++ b/readconf.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: readconf.c,v 1.418 2026/10/03 00:46:29 djm Exp $ */
+/* $OpenBSD: readconf.c,v 1.419 2026/10/05 06:03:40 dtucker Exp $ */
/*
* Author: Tatu Ylonen <ylo at cs.hut.fi>
* Copyright (c) 1995 Tatu Ylonen <ylo at cs.hut.fi>, Espoo, Finland
@@ -3461,14 +3461,11 @@ ssh_valid_ruser(const char *s)
for (i = 0; s[i] != 0; i++) {
if (iscntrl((u_char)s[i]))
return 0;
- if (strchr("'`\";&<>|(){}", s[i]) != NULL)
+ if (strchr("'`\";&<>|(){}$\\", s[i]) != NULL)
return 0;
/* Disallow '-' after whitespace */
if (isspace((u_char)s[i]) && s[i + 1] == '-')
return 0;
- /* Disallow \ in last position */
- if (s[i] == '\\' && s[i + 1] == '\0')
- return 0;
}
return 1;
}
--
To stop receiving notification emails like this one, please contact
djm at mindrot.org.
More information about the openssh-commits
mailing list