OpenSSH 10.6 disables LZ77 in SSH compression after side-channel research
OpenSSH 10.6 adds a hybrid post-quantum signature algorithm as the project says it will ship security fixes more often.
By RuntimeWire Staff · Published
Primary source: OpenSSH
Why it matters
OpenSSH is embedded across operating systems and commercial products, so changes to compression and the release cadence affect a wide range of deployments. The compression change reduces efficiency to address a side channel that could expose secret data under specific conditions.

OpenSSH 10.6 was released October 6th, disabling the LZ77 dictionary coder in SSH compression to address a cross-channel side channel researchers demonstrated earlier this year. The release also adds a hybrid post-quantum signature algorithm and changes how the project handles security fixes. Maintainers say they will release more frequently instead of waiting to bundle fixes.
OpenSSH is maintained by developers associated with the OpenBSD Project. Its early builders included Theo de Raadt, Niels Provos, Markus Friedl, Bob Beck, Aaron Campbell and Dug Song. In 1999, they took on the practical work of making SSH code usable under a permissive license and maintaining it. The project's history says the first OpenSSH release shipped with OpenBSD 2.6 in December 1999.
Compression takes a back seat to confidentiality
The central change responds to research by Fabian Baumer and Marcus Brinkmann. Their paper, "Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels", describes how an attacker could use chosen input on one SSH channel and observe ciphertext lengths to recover secret data sent on another. The method depends on multiple conditions, including compression and attacker access to a channel that can carry chosen input. The researchers say how often those conditions coincide in real deployments is not known.

OpenSSH's fix disables the LZ77 dictionary coder, making the Compression option less effective. The release notes recommend application-level compression where practical. Administrators who rely on SSH compression to reduce traffic may see less benefit, while the project removes the shared dictionary behavior implicated in the attack. The maintainers had already advised against enabling compression on connections that mix trusted and untrusted traffic.
The response is one of several security fixes in 10.6. The SFTP client now validates paths returned by a server more strictly to prevent certain malicious responses from steering recursive copies outside their intended target directory. The release also changes GSSAPI authentication handling so credentials from failed attempts are not retained for later use, and resets authentication state between attempts.
Other fixes address command-line usernames containing dollar signs or backslashes, which could create shell-injection risks in some configurations; compressed payloads exceeding the supported packet size; and the handling of the authorized_keys restrict keyword for tunnel forwarding. These are specific hardening measures, not a claim that every configuration was exposed to each issue.
A release cadence shaped by security reports
The OpenSSH maintainers say they have received a large number of security reports based on AI model findings or AI-assisted analysis. They say many do not amount to security issues under a realistic threat model, while also noting that some AI-identified bugs were later found independently by another researcher. Their stated response is to make releases more frequently so fixes reach users sooner.
The release notes do not quantify the reports or say how many produced fixes. OpenSSH is incorporated into commercial products, but the project says few of those companies help fund its work. Its maintenance relies on community reports, code, testing and donations.
OpenBSD's account says the original team moved quickly toward the OpenBSD 2.6 release, simplifying code and removing licensing obstacles as they built a freely reusable implementation. That work helped create infrastructure now relied on across operating systems and commercial products.
Post-quantum support and compatibility changes
The release enables a hybrid post-quantum signature algorithm, ssh-mldsa44-ed25519, combining ML-DSA-44 with Ed25519. OpenSSH also adds a server-side WarnWeakCrypto option, enabled by default, to log when a client uses a key-agreement method that is not post-quantum safe. Users of keys created with the previous experimental version of the hybrid algorithm must regenerate or remove those keys, according to the release notes.
There are compatibility changes too. The remote-to-remote scp -R option continues to work in 10.6 but now produces a deprecation warning; the project says a future release will ignore it. The notes also warn that support may be removed for certain older platforms that cannot pass file descriptors and require root privileges for PTY allocation, including SCO OpenServer 5 and QNX 6 under the specified conditions.
Administrators should review the fixes and check whether they rely on SSH compression, older SCP workflows or experimental post-quantum keys.