Команда OpenSSH, набора программ для защищённого удалённого доступа, выпустила версию 10.6 с исправлениями безопасности в копировании файлов и сжатии данных. Разработчики подтвердили, что пока будут выпускать исправления чаще, не дожидаясь плановых релизов.
Клиент sftp, программа для передачи файлов, теперь строже проверяет пути, полученные от сервера. Раньше сервер иногда мог при копировании папок со всем содержимым заставить клиента записать файлы за пределами выбранного каталога.
В клиенте и сервере отключили часть алгоритма сжатия, чтобы затруднить извлечение секретов из одного канала SSH-соединения через другой. Из-за этой защиты сжатие стало менее эффективным, поэтому команда рекомендует по возможности сжимать данные в самих приложениях.
Проверка утверждений:
- Команда OpenSSH выпустила версию 10.6 с исправлениями безопасности и подтвердила, что пока будет выпускать исправления чаще, не дожидаясь плановых релизов. (подтверждено самой публикацией: доказательство; «OpenSSH 10.6 was released on 2026-10-06. It is available from the mirrors listed at https://www.openssh.com/ . OpenSSH is a 100% complete SSH protocol 2.0 implementation and includes sftp client and server support. Recently the OpenSSH team have received a large number of security bug reports, many of which are findings from AI models or made with AI assistance. While many AI reports are determined not to have security impact when considered in the context of a realistic threat model, we very much welcome these reports, especially when combined with human triage, analysis, test-cases and particularly when accompanied by proposed fixes. ** We have seen a number of cases where a security bug identified ** by AI tools is subsequently independently discovered by a ** different researcher. This suggests that adversaries who do not ** report bugs to OSS projects are likely to be able to discover ** these bugs too. Given this, the OpenSSH team will, for now, be ** making more frequent releases to get bugfixes into users’ hands ** more quickly rather than batching them until the next planned ** release.»)
- В OpenSSH 10.6 исправлены ошибки безопасности при копировании файлов и изменено сжатие данных для защиты от утечки секретов. (подтверждено самой публикацией: доказательство; «* sftp(1) : more strictly validate paths returned from the server to avoid some cases where a server could return paths that could manipulate a recursive copy operation into writing outside its target directory. Report and patch from Junghoon Cho. * sshd(8) : when GSSAPIAuthentication is in use, only store GSSAPI credentials when authentication has succeeded. Avoids a situation where credentials from a failed GSSAPIAuthentication attempt may persist and be made inappropriately available if another authentication subsequently succeeds. Issue report and patch from Moritz Theile. * sshd(8) : reset GSSAPIAuthentication before authentication, avoiding state from one authentication attempt being confused with that of a later attempt. Report and feedback from Moritz Theile. * sshd(8) , ssh(1) : disable LZ77 dictionary coder to mitigate the side-channel leaks described in “Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels” by Fabian Bäumer and Marcus Brinkmann, preprint https://arxiv.org/abs/2609.07709 (2026) A chosen-plaintext attack method exists which makes use of dictionary-based compression to recover secrets from one channel by interacting with the SSH session’s shared compression dictionary through another channel. Attacker-controlled input can recognizably reflect into the total length of transmitted ciphertexts by virtue of LZ77 replacing repeated strings with back-references into the SSH session’s encoder search buffer, which is shared across all channels. For this reason, the documentation already recommended against enabling compression for connections that share trusted and untrusted traffic. This change will reduce the effectiveness of the Compression option. Users are encouraged to use application-level compression over the SSH protocol where possible, as this will typically be more effective and will be completely immune to this type of attack.»)
- Клиент sftp теперь строже проверяет пути, полученные от сервера. (подтверждено самой публикацией: доказательство; «* sftp(1) : more strictly validate paths returned from the server to avoid some cases where a server could return paths that could manipulate a recursive copy operation into writing outside its target directory. Report and patch from Junghoon Cho.»)
- Раньше сервер в некоторых случаях мог при рекурсивном копировании заставить клиента записать файлы за пределами выбранного каталога. (подтверждено самой публикацией: доказательство; «* sftp(1) : more strictly validate paths returned from the server to avoid some cases where a server could return paths that could manipulate a recursive copy operation into writing outside its target directory. Report and patch from Junghoon Cho.»)
- В клиенте и сервере отключили часть алгоритма сжатия, чтобы затруднить извлечение секретов из одного канала SSH-соединения через другой. (подтверждено самой публикацией: доказательство; «* sshd(8) , ssh(1) : disable LZ77 dictionary coder to mitigate the side-channel leaks described in “Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels” by Fabian Bäumer and Marcus Brinkmann, preprint https://arxiv.org/abs/2609.07709 (2026) A chosen-plaintext attack method exists which makes use of dictionary-based compression to recover secrets from one channel by interacting with the SSH session’s shared compression dictionary through another channel.»)
- Из-за этой защиты сжатие стало менее эффективным, поэтому команда рекомендует по возможности сжимать данные в самих приложениях. (подтверждено самой публикацией: доказательство; «This change will reduce the effectiveness of the Compression option. Users are encouraged to use application-level compression over the SSH protocol where possible, as this will typically be more effective and will be completely immune to this type of attack.»)
Первоисточники:
оценка 59,5 из 100 · тип: релиз