04
OpenSSH 10.6 changes compression behavior and requires replacing experimental keys
The OpenSSH team released version 10.6 on Oct. 6 and said it plans more frequent releases for now. The update disables the LZ77 dictionary coder after researchers described a cross-channel secret-recovery attack, and includes fixes involving GSSAPI credentials, SFTP paths and username handling. It enables the hybrid post-quantum signature algorithm ssh-mldsa44-ed25519; maintainers say keys made with earlier experimental support must be regenerated or removed.
What changed GSSAPI credential storage now waits for successful authentication; previously, credentials from a failed attempt could survive and become exposed after a later successful login.
Why it matters Operators who tested the hybrid signature algorithm have a key-maintenance task alongside the software update: existing experimental keys cannot simply be carried forward unchanged.
What to watch next The team plans a faster release cadence to deliver bug fixes. Operators should watch for subsequent releases, but the source gives no next-release date.
HelpNet Security ↗