OpenSSH 10.4 arrives with security fixes and a post-quantum signature option
ID: 496aa976-48e5-5843-97c2-8ec87a8782c5
STIX ID: report--496aa976-48e5-5843-97c2-8ec87a8782c5
Feed Name: Help Net Security
OpenSSH 10.4 was released with eight security fixes, various bug corrections, and new features (including an experimental ML-DSA/Ed25519 composite signature and a new nondeterministic-finite-automaton wildcard matcher). Fixes address sftp path redirection and scp writes to parent directories when interacting with malicious servers, sshd internal-sftp argument truncation, a pre-authentication DoS with GSSAPI, enforcement of minimum authentication delay, a client use-after-free on host-key reexchange, ed25519 validity checks and signature malleability protections, and additional hardening; several behavioral changes may break existing configurations (sshd -G casing, stricter seccomp/NO_NEW_PRIVS requirements, and stricter post-auth rekey handling).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
