Multiple OpenSSH Vulnerabilities Could Enable Plaintext Recovery, File Write and Injection Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


OpenSSH 10.6, released on October 6, 2026, fixes security flaws that could expose secrets, write files outside intended folders, or enable shell injection under specific conditions. The update covers both client and server tools, making it relevant to administrators and users who rely on SSH for remote access and file transfers.

The official release notes describe separate weaknesses with different attack requirements, not a single attack affecting every installation. The main concerns involve shared compression across SSH channels, paths returned by SFTP servers, and untrusted usernames passed to shell commands.

SSH Plaintext Recovery Risk

Researchers Fabian Bäumer and Marcus Brinkmann describe the compression flaw in Crossing the Streams. When compression is enabled, channels within one SSH connection share a compression dictionary. An attacker who can place chosen text into one channel and watch encrypted traffic lengths can use those changes to recover secrets carried through another channel.

The leak comes from LZ77 compression, which replaces repeated text with references to earlier data. If attacker-controlled text matches part of a secret, the resulting traffic length can reveal clues. This does not directly break SSH encryption; it uses information exposed by compression before encryption takes place.

In the researchers’ lowest-noise test, an eight-character secret drawn from a 26-letter alphabet could be recovered with at most 276 guesses. That result depends on the tested conditions and should not be read as a universal recovery rate.

OpenSSH 10.6 disables the LZ77 dictionary coder in both ssh and sshd. Compression remains available but becomes less effective. The developers recommend application-level compression where possible, rather than sharing SSH compression between trusted and untrusted traffic.

File Write And Injection Flaws

The SFTP fix strengthens checks on paths returned by a server. Before this change, a malicious server could provide paths that steer a recursive copy into writing outside its target directory. Researcher Junghoon Cho reported the issue and supplied a patch. The risk concerns client handling of server responses, rather than an unauthenticated attacker writing to any SSH server.

Another fix blocks dollar signs and backslashes in destination usernames supplied on the SSH command line. In some configurations, names from untrusted sources could reach shell contexts through ProxyCommand, Match exec, or related features and cause injection.

SecBuddyF KeenLab Tencent reported this issue. Usernames set through the User directive in configuration files remain outside the new restriction. OpenSSH warns that character filtering cannot fully cover every shell and setup, so applications should not pass untrusted input directly into SSH command lines.

Cybersecurity News previously covered OpenSSH 10.3 shell injection fixes, providing useful background on earlier username and ProxyJump checks. Those fixes are separate from the protections introduced here.

The release also corrects GSSAPI credential handling, tunnel restrictions, oversized decompressed packets, and certificate date conversion. On certain older platforms, including QNX 6 and SCO OpenServer 5, it disables forwarding options linked to retained root privileges.

Administrators should review these changes when deploying the update, especially where compression or forwarding is required. Meanwhile, maintainers plan more frequent releases as AI-assisted reports increase, warning that attackers may independently discover the same bugs. Human review, test cases, and proposed fixes remain important to validating those reports.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

The post Multiple OpenSSH Vulnerabilities Could Enable Plaintext Recovery, File Write and Injection Attacks appeared first on Cyber Security News.