Database/Kernel, userspace & hypervisor

OpenSSH before 10.6: LZ77 dictionary coder usable despite compression side-channel findings
Impact
OpenSSH before 10.6 can still use an LZ77 dictionary coder in its compression path, which the referenced "Crossing the Streams" research argues against. The scored impact is limited confidentiality loss with high attack complexity and no privilege required - a passive or on-path observer may infer something about session contents from compressed traffic. On a GPU fleet, sshd is the control path to every bastion, login node and management host, so compression behaviour is worth knowing about; but the record describes a weakness in a cryptographic/compression choice, not a code-execution or auth bypass, and gives no concrete exploitation scenario beyond the paper. Keep expectations at that level.
Who can reach it
Network, unauthenticated, but requires the ability to observe SSH traffic and high attack complexity per the CVSS vector. Affects sessions where compression is negotiated, on both the client (ssh) and server (sshd) side.
What to do
Fixed in OpenSSH 10.6 per the release notes. Upgrade the OpenSSH packages on login nodes, bastions and management hosts and restart sshd - existing sessions survive a restart, so this is a daemon restart rather than a reboot. As an interim measure, disabling compression (Compression no in sshd_config, -o Compression=no for clients) removes the path the finding depends on.
References
Related entries
- OpenSSL: non-constant-time SM2 point multiplication on AArch64 and RISC-V leaks key bits via timing and cacheCVE-2026-54875 · OpenSSL (SM2 scalar multiplication on AArch64 and RISC-V)Low
- OpenSSH: heap out-of-bounds read during GSSAPI indicator cleanup crashes the authentication pathCVE-2026-55654 · OpenSSH sshd (GSSAPI auth-indicator cleanup)Low
- strongSwan: PKCS#7 certificate enumeration in the openssl plugin leaks memoryCVE-2026-78124 · strongSwan openssl plugin (PKCS#7 certificate enumeration)Low
- OpenSSH sshd: the value "none" is sometimes treated as a filename instead of disabling the featureCVE-2026-106587 · OpenSSH sshd (configuration option value "none")Low
- OpenSSH ssh-agent: locking bypass lets a forwarded remote session add tokens and use keysCVE-2026-73281 · OpenSSH ssh-agent (agent locking vs session-bind@openssh.com extension)Low
- Linux kernel mlx5_ib (create QP response): mlx5_ib_create_qp_resp is never initialized in create_qp_common, so creatingCVE-2018-20855 · Linux kernel mlx5_ib (create QP response)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.