Release of OpenSSH 10.5

OpenSSH 10.5, an open-source client and server implementation for SSH 2.0 and SFTP, has been released. Key changes include:

  • The portable version of OpenSSH now requires support for elliptic curve cryptography (ECC) in the libcrypto library, including support for the NISTP521 elliptic curve. This support is enabled by default in the libcrypto implementations from the LibreSSL, OpenSSL, BoringSSL, and AWS LC projects.
  • When resetting the password for private keys for FIDO tokens, the ssh-keygen utility now sets the touch-required and verify-required flags, which require confirmation from the user.
  • The ssh utility has changed the order in which certificates are used for public key authentication: FIDO keys that do not require user action are now used first, and keys that require PIN or biometric verification are used last.
  • Added "ssh -Z user" command to list keys in the order they are used for public key authentication.
  • Fixed security issues:
    • Fixed incorrect handling of session binding requests when SSH Agent was blocked, which resulted in SSH Agent allowing remote operations that should only be available locally, such as adding PKCS#11 tokens and using keys linked to specific servers in the settings, instead of denying access.
    • In the ssh client, a potential use-after-free issue has been eliminated that occurs when multiplexing SSH connections through a single socket if a new port forwarding is added while the client is still waiting for Server response to the opening of the previous pass.
    • sshd now correctly applies restrictions set via the "restrict" flag in the authorized_keys file to forwarded tunnels.

Source: opennet.ru

Buy reliable hosting for sites with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster