OpenSSH 10.6
torcete
103 points
25 comments
October 06, 2026
Related Discussions
Found 5 related stories in 96.9ms across 8,687 title embeddings via pgvector HNSW
- OpenSSH 10.5/10.5p1 voxadam · 109 pts · August 11, 2026 · 92% similar
- Show HN: OxiSH, a modern, memory-safe SSH server dochtman · 19 pts · August 13, 2026 · 54% similar
- OpenSSH Ships on Every Mac, Linux Server and Windows. Its Creator Trusts No One zbruceli · 21 pts · October 05, 2026 · 54% similar
- TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access jervant · 101 pts · July 15, 2026 · 52% similar
- OxiSH: SSH Server Written in Rust wofo · 16 pts · August 13, 2026 · 47% similar
Discussion Highlights (7 comments)
FloatArtifact
" * We have seen a number of cases where a security bug identified * by AI tools is subsequently independently discovered by a * different researcher. This suggests that adversaries who do not * report bugs to OSS projects are likely to be able to discover * these bugs too. Given this, the OpenSSH team will, for now, be * making more frequent releases to get bugfixes into users' hands * more quickly rather than batching them until the next planned * release."
brynet
> sshd(8): On OS X SDK >= 27, sandboxing is no longer supported as the API we depended upon has been removed and no obvious alternative provided. https://github.com/openssh/openssh-portable/commit/d4b4c304a...
po1nt
I think this is much healthier approach to AI reports than curl has. But I understand both sides.
robinpie
Really glad to see the rate of security fixes speeding up.
ilaksh
They mention a donation link: https://www.openbsd.org/donations.html I wonder what their funding is like.
davb
I found a small bug in QoS handling in the OpenSSH client under specific conditions. It had a big impact on my workflow but wasn’t a complete showstopper and might not have had an obvious impact on the broader user base. I raised an issue on the tracker and within a day I had a test build, a confirmed fix and a note of which release would carry the fix. It was one of the most positive experiences I’ve had reporting a bug, especially for a non-security issue. I know this comment doesn’t add much to the conversation about this release, but I’m very grateful to Damien (who handled the issue) and the team for the wonderful job they’re doing on such a core piece of software.
tptacek
The big ticket thing here seems to be mitigation of "Crossing The Streams", a CRIME-style compression side channel that relies on the fact that different sessions share LZ77 state: https://arxiv.org/pdf/2609.07709