Release of OpenSSH 9.1

After six months of development, OpenSSH 9.1 has been released, which is an open implementation of a client and server for working with SSH 2.0 and SFTP protocols. The release is characterized mainly by bug fixes, including several potential vulnerabilities caused by memory handling issues:

  • Single-byte overflow in the SSH banner handling code in the ssh-keyscan utility.
  • Double call to the free() function in case of an error when computing hashes for files in the code for creating and verifying digital signatures in the ssh-keygen utility.
  • Double call to the free() function when handling errors in the ssh-keysign utility.

Key Changes:

  • A RequiredRSASize directive has been added to ssh and sshd, allowing users to specify the minimum allowable size for RSA keys. In sshd, smaller keys will be ignored, while in ssh this will result in the termination of the connection.
  • The portable version of OpenSSH has been switched to using SSH keys for signing commits and tags in Git.
  • The SetEnv directives in the ssh_config and sshd_config configuration files now apply the value from the first mention of an environment variable if it is defined multiple times in the configuration (previously, the last mention was used).
  • When invoking the ssh-keygen utility with the flag '-A' (to generate all supported default types of host keys), the generation of DSA keys, which have not been used by default for several years, has been disabled.
  • The 'users-groups-by-id@openssh.com' extension has been implemented in sftp-server and sftp, allowing the client to request user and group names corresponding to the specified set of digital identifiers (uid and gid). In sftp, this extension is used to display names when outputting directory contents.
  • The 'home-directory' extension has been implemented in sftp-server to resolve paths ~\/ and ~user\/, an alternative previously proposed for the same purposes is the 'expand-path@openssh.com' extension (the 'home-directory' extension is proposed for standardization and is already supported by some clients).
  • The ability to specify time in the UTC timezone when defining the validity periods of certificates and keys has been added to ssh-keygen and sshd, in addition to system time.
  • In sftp, it is now allowed to specify additional arguments in the '-D' option (for example, '/usr/libexec/sftp-server -el debug3').
  • The -U flag (using ssh-agent) is allowed in ssh-keygen along with the -Y sign operations to specify that private keys are stored in ssh-agent.

    Source: opennet.ru
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster