Dettaglio notizia

Data 07/07/2026
Titolo OpenSSH 10.4 fixes multiple flaws and adds optional post-quantum signatures
Contesto OpenSSH has released version 10.4 with eight security fixes affecting both client and server components, including sftp, scp, sshd, ssh, ssh-agent, and cryptographic verification logic. The update addresses path traversal-style and file redirection issues that could let a malicious server write files outside intended locations, a pre-authentication denial-of-service condition in sshd, a client-side use-after-free bug, and gaps in authentication delay enforcement. The release also replaces the wildcard matcher with an NFA-based implementation to remove exponential worst-case behavior.

The release introduces experimental support for a composite post-quantum signature scheme combining ML-DSA 44 with Ed25519, available only when explicitly enabled and configured. OpenSSH also hardened protocol handling by disconnecting peers that send non-KEX messages during post-authentication rekeying and made seccomp sandbox initialization failures fatal on Linux. Maintainers warned that some changes may break existing deployments, including mixed-case output from sshd -G, stricter transport-layer behavior, and the new sandbox failure handling.
Fonte https://mallory.ai/stories/019f37c4-f905-7a75-ba72-735830fd429b
Discussione? Parliamone sul Forum