OpenSSH 10.6 was released on October 6, 2026, less than two months after 10.5 (August 11). In our previous article we went through the changes in 10.4 and 10.5 that could lock you out; this release is mainly a run of security fixes, two of which change existing behaviour.

The Security Fixes Worth Your Attention

  • Compression side channel: the LZ77 dictionary coder is disabled to mitigate the side-channel leaks described in the "Crossing the Streams" research by Bäumer and Brinkmann. The cost is weaker compression on connections that use it.
  • Command-line username injection: usernames entered on the command line may no longer contain $ or \, so a username from an untrusted source can't turn into injection in a shell context. If your scripts splice outside data into ssh user@host, this fix is for you.
  • sftp recursive downloads: paths returned by the server are validated more strictly, so a malicious server can't steer a recursive copy into writing outside its target directory.
  • GSSAPI: two fixes ensure credentials from a failed authentication attempt are no longer stored.
  • The restrict keyword in authorized_keys now applies properly to tunnel forwarding. If you put restrict on a key while the server has PermitTunnel enabled, that key could previously still request a tunnel.
  • Also: compressed payloads may not exceed the maximum packet length; parsing of options set to none inside Match blocks is fixed; and ssh-keygen no longer gets certificate dates wrong by up to an hour around daylight saving time.

Two Changes That May Affect Existing Use

  • Stricter username validation: usernames containing $ or \ on the command line are rejected. Usernames in configuration files are not affected by this rule; check your automation.
  • On platforms without file descriptor passing, GatewayPorts and StreamLocalForwarding are forcibly disabled. Mainstream Linux distributions are not among them.

New Features Relevant to Server Operators

The hybrid post-quantum signature algorithm ssh-mldsa44-ed25519 is now enabled; sshd gains a WarnWeakCrypto option that flags weak algorithms; sftp supports mkdir -p; ChannelTimeout accepts fractional seconds; and a new AgentSocketPath option sets where the agent socket lives.

How to Upgrade

Most distributions won't push the whole of 10.6 to their stable releases right away; they backport the security fixes to the version they ship, so read your distro's security advisories rather than watching the version number. Before upgrading sshd, keep one session logged in, run sshd -t to check the configuration, then restart the service so you can't lock yourself out. For SSH basics see connecting to a Linux VPS over SSH (passwords and keys); if you can't get in after the upgrade, work through the SSH connection troubleshooting checklist; and while you're there, review your firewall and key-based login.