OpenSSH 10.3 patches five security bugs and drops legacy rekeying support
ID: 75fdaab5-6434-5e5b-b5fe-4b7c687e1f99
STIX ID: report--75fdaab5-6434-5e5b-b5fe-4b7c687e1f99
Feed Name: Help Net Security
OpenSSH 10.3 release notes: this advisory describes several security fixes and compatibility changes for widely used OpenSSH components. Key items include removal of rekeying compatibility (potential interoperability breaks), a validation-timing flaw that could allow shell metacharacter expansion from command-line usernames, a certificate principal matching bug and a change treating empty certificate principals as non-matching, fixes for ECDSA algorithm enforcement, scp preserving setuid/setgid bits when downloading as root, ProxyJump input validation, multiplexing confirmation fixes, ssh-agent protocol additions, and new per-source penalty controls and diagnostic commands. Administrators should review configurations (particularly legacy or nonstandard implementations, Match exec usage with %u tokens, and user-trusted CA/authorized_keys usage) prior to upgrading and apply mitigations where appropriate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
