logo

OpenSSH 10.4 arrives with security fixes and a post-quantum signature option

ID: 496aa976-48e5-5843-97c2-8ec87a8782c5

STIX ID: report--496aa976-48e5-5843-97c2-8ec87a8782c5

Feed Name: Help Net Security

Threat Score
45/100

Date Published: 2026-07-06

Date Updated: 2026-07-06

Author: Anamarija Pogorelec

...
...

OpenSSH 10.4 was released with eight security fixes, various bug corrections, and new features (including an experimental ML-DSA/Ed25519 composite signature and a new nondeterministic-finite-automaton wildcard matcher). Fixes address sftp path redirection and scp writes to parent directories when interacting with malicious servers, sshd internal-sftp argument truncation, a pre-authentication DoS with GSSAPI, enforcement of minimum authentication delay, a client use-after-free on host-key reexchange, ed25519 validity checks and signature malleability protections, and additional hardening; several behavioral changes may break existing configurations (sshd -G casing, stricter seccomp/NO_NEW_PRIVS requirements, and stricter post-auth rekey handling).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.