The update removes support for the LZ77 dictionary coder used in SSH compression after researchers Fabian Bäumer and Marcus Brinkmann of Ruhr University Bochum demonstrated that sharing compression state across multiple channels within a single SSH session could allow an attacker to recover plaintext. In their paper, "Crossing the Streams," they showed that an attacker who can feed chosen data into one channel and observe the resulting encrypted traffic can infer secrets moving through another channel. The attack exploits LZ77's memory: when a guess matches part of a secret, the compressed output becomes slightly smaller, leaking information.
The other change blocks the dollar sign ($) and backslash () in command-line usernames to prevent them from being interpreted by the shell through directives such as ProxyCommand and Match exec.
OpenSSH leaves compression off by default, so the vulnerability only affects sessions where it is explicitly enabled. In their lowest-noise tests, the researchers recovered an eight-character secret from a 26-character alphabet in a median of 276 guesses across 100 trials.
The release notes warned that adversaries who do not report vulnerabilities "are likely to be able to discover these bugs too." The project indicated it will now release fixes more frequently rather than adhere to its usual schedule, as security research — including AI-assisted analysis — increases the pace of discovery.