OpenSSH 10.6 Released: Post-Quantum Signatures and a Fix for a Novel Compression Side-Channel
The project says AI-generated bug reports are pushing it to ship fixes more often, and it's disabling a compression option to kill a new side-channel attack.
OpenSSH 10.6 dropped today. It's the latest point release in the 10.x series, roughly a year after 10.5, and it arrives with a heavier-than-normal stack of security fixes, a now-standard post-quantum signature algorithm, and a somewhat uncomfortable admission about where today's vulnerabilities come from.
The new version ships as openssh-10.6.tar.gz and a first patch build, openssh-10.6p1.tar.gz, available on the usual mirrors. Here's the part that makes it worth more than a routine security bump: the team says a lot of the bug reports it's been receiving recently come from AI models, and it plans to ship fixes more often as a result.
AI-discovered bugs are changing the release cadence
The announcement opened with an off-the-cuff note. The maintainers reported they'd received "a large number of security bug reports, many of which are findings from AI models or made with AI assistance." They were clear that many of these don't actually matter once you put them in a realistic threat model. They weren't going to quietly discard the flood either.
"We have seen a number of cases where a security bug identified by AI tools is subsequently independently discovered by a different researcher," the team wrote. That single line is doing a lot of heavy lifting. It's effectively an admission: if an AI can find a bug, so can a malicious actor who isn't in the habit of filing it responsibly. The response isn't to scrutinize reporters harder. It's to release more often.
Several of the 10.6 patches carry the fingerprint of that reasoning. A few are credited "with Chris Rohlf in collaboration with Claude and Anthropic Research." That's a tell. The maintainers have formalized a working relationship with the lab behind Claude, and it's now sitting right in the attribution line. It matters more than you'd think, especially as AI-assisted disclosure has become something to actually plan around over the past year.
The compression side-channel the update exists to squash
The headline fix disables the LZ77 dictionary coder to blunt a side-channel leak called "Crossing the Streams," named after the preprint by Fabian Bäumer and Marcus Brinkmann of Ruhr University Bochum (arXiv:2609.07709, later accepted at ACM CCS 2026).
SSH multiplexes several logical channels: interactive shells, commands, port forwarding, agent connections, all over a single encrypted connection. All of them share one compression context at the Binary Packet Protocol layer. Enable compression and an attacker who can inject half-chosen plaintext into one channel and watch ciphertext lengths on the network can run a chosen-plaintext attack to pull secrets out of another channel.
The researchers frame it as SSH's answer to CRIME and BREACH, the compression side-channels that plagued HTTP over TLS for years. They note it's the first one ever aimed at SSH itself.
It's not a magic remote-exploit, and it's fair to say so. Even the paper's best-case numbers are rough. In the quietest environment they tested, an eight-character secret pulled from a 26-letter alphabet could be recovered in at most 276 guesses. They built proof-of-concept runs against direct plaintext injection, browser-based injection into a forwarded port, and an Ansible sudo password sent over a session channel. They also surveyed 33 SSH clients and found compression was the default in only four.
OpenSSH's response kills the LZ77 dictionary coder, which "will reduce the effectiveness of the Compression option." The advice is to lean on application-level compression where you can, since that "will be completely immune to this type of attack." It's a rather expensive tradeoff for a compression tweak, though the side-channel is real, so the mitigation is arguably earned.
A tighter batch of other fixes
The rest of the security work spans the usual spread: auth-state bugs, privilege-escalation paths, input-validation gaps. A few worth naming.
ssh(1) now refuses $ and \ in command-line usernames, closing an injection path into ProxyCommand and Match exec contexts. It doesn't touch usernames coming from config files. GSSAPI handling in sshd(8) now stores credentials only after a successful login and resets state between attempts, so a failed auth can't leak into the next one. Compressed payloads can no longer inflate past the packet-length cap.
There's also a quiet upgrade to key stretching. The default number of KDF rounds jumped from 24 to 32, and a cap of 1M rounds was added so a maliciously crafted key can't make parsing spin forever. The team pointed out that's a linear bump, unlike bcrypt, where each round compounds exponentially.
Post-quantum keys now need regenerating
On the feature side, 10.6 makes the hybrid post-quantum signature algorithm ssh-mldsa44-ed25519 standard everywhere. The catch is timing. This version drops the @openssh.com vendor suffix that the experimental version required, which means keys built with the old experimental support are no longer usable. If you generated one, regenerate it.
sshd(8) also gains WarnWeakCrypto, enabled by default, which logs when a client negotiates a key-agreement scheme that isn't post-quantum safe. It gives admins a way to see where weak crypto is still in use on their hosts.
The rest is mostly polish. FIDO resident keys now respect their credential-protection policy, ssh-add(1) gets a -P flag for tokens that don't need a PIN, ssh-keygen(1) can dump keys in hexdump form, and ChannelTimeout now accepts fractional seconds. Servers can count "key ok" probes separately from failed logins via the new PubkeyOptions max-pk-ok option, so clients can try more keys before getting kicked off.
Things that will change under you
Three deprecations deserve a spot on your radar. The scp -R flag, which does remote-to-remote copies by shelling out on a host, is now flagged as a fragile optimisation with quoting-based risks. It still works but warns. It'll be ignored in a later release.
Second, OpenSSH is moving away from SCO OpenServer 5 and QNX 6, plus any build configured with --disable-fd-passing. On those platforms, sshd now forces GatewayPorts and StreamLocalForwarding off, and full support is slated for removal entirely.
Third, and tied to the headline fix, compression effectiveness is down. If you lean on SSH compression for bandwidth-starved multiplexed sessions, budget for smaller ratios or move compression up to the application.
Where to get it
The portable archives are openssh-10.6.tar.gz and openssh-10.6p1.tar.gz, signed with the PGP key at cdn.openbsd.org. Keep in mind that the published SHA256 digests are base64-encoded, not the usual hex output. That trips people up who expect plain hex, so set your checksum tooling accordingly.
Operators of SSH servers and clients should plan to upgrade, chiefly for the compression mitigation, the username-injection fix, and the GSSAPI corrections. Anyone holding old experimental post-quantum keys should regenerate them now. Head here for the full patch notes and the October 6 release announcement.
