OpenSSH 10.6 Intentionally Breaks Features to Patch Security Vulnerabilities

Update disables compression sharing and blocks special characters in usernames after researchers demonstrate plaintext recovery risk

By LineZotpaper
Published
Read Time2 min
The OpenSSH project released version 10.6 on Tuesday, deliberately disabling the LZ77 compression coder and blocking certain characters in command-line usernames to close security holes that could expose encrypted traffic. The maintainers acknowledged the changes would break existing configurations but argued the risks justified the disruption.

The update removes support for the LZ77 dictionary coder used in SSH compression after researchers Fabian Bäumer and Marcus Brinkmann of Ruhr University Bochum demonstrated that sharing compression state across multiple channels within a single SSH session could allow an attacker to recover plaintext. In their paper, "Crossing the Streams," they showed that an attacker who can feed chosen data into one channel and observe the resulting encrypted traffic can infer secrets moving through another channel. The attack exploits LZ77's memory: when a guess matches part of a secret, the compressed output becomes slightly smaller, leaking information.

The other change blocks the dollar sign ($) and backslash () in command-line usernames to prevent them from being interpreted by the shell through directives such as ProxyCommand and Match exec.

OpenSSH leaves compression off by default, so the vulnerability only affects sessions where it is explicitly enabled. In their lowest-noise tests, the researchers recovered an eight-character secret from a 26-character alphabet in a median of 276 guesses across 100 trials.

The release notes warned that adversaries who do not report vulnerabilities "are likely to be able to discover these bugs too." The project indicated it will now release fixes more frequently rather than adhere to its usual schedule, as security research — including AI-assisted analysis — increases the pace of discovery.

§

Analysis

Why This Matters

  • The changes affect organisations and individuals that rely on SSH compression for bandwidth efficiency over slow connections, or that use special characters in usernames for scripting or automated access.
  • The deliberate breaking of features signals a shift toward proactive security hardening in critical infrastructure software, even when it causes user disruption.
  • The increased patch cadence from OpenSSH means sysadmins will need to keep closer track of releases, but also that vulnerabilities may be addressed before they are actively exploited.

Background

OpenSSH is the most widely used implementation of the SSH protocol, providing encrypted remote access and file transfer for servers, network devices and cloud infrastructure. It has a long history of conservative development, prioritising stability and backward compatibility. The compression attack disclosed in this release belongs to the same family as the CRIME and BREACH attacks against TLS, which also exploited shared compression contexts. Security research has intensified in recent years, with AI models increasingly able to identify subtle flaws in cryptographic implementations.

Key Perspectives

OpenSSH maintainers: They chose to ship breaking changes rather than risk leaving a proven vulnerability unaddressed. The release notes acknowledge the impact but frame it as necessary given that adversaries are likely to discover these bugs independently. Security researchers: Bäumer and Brinkmann demonstrated a practical attack requiring specific conditions (compression enabled, multiplexed channels) but showing real plaintext recovery. Their work adds to a growing body of research on side-channel attacks in encrypted protocols. System administrators and users: Those who depend on SSH compression for low-bandwidth links or who use special characters in automated authentication flows will need to update configurations or scripts. Some may question whether the breakage could have been avoided through more targeted fixes, such as isolating compression contexts per channel.

What to Watch

  • Whether any proof-of-concept exploits emerge in the wild targeting the compression vulnerability before administrators disable compression.
  • How quickly OpenSSH ships follow-up releases addressing other bugs found via AI-assisted scanning.
  • Community reaction and whether alternative implementations (e.g., Dropbear, libssh) adopt similar hardening measures.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.