GPU VulnDB

Database/Kernel, userspace & hypervisor

OpenSSH before 10.6: LZ77 dictionary coder usable despite compression side-channel findings

CVSS 3.7CVE-2026-106582Kernel, userspace & hypervisorcurated

Impact

OpenSSH before 10.6 can still use an LZ77 dictionary coder in its compression path, which the referenced "Crossing the Streams" research argues against. The scored impact is limited confidentiality loss with high attack complexity and no privilege required - a passive or on-path observer may infer something about session contents from compressed traffic. On a GPU fleet, sshd is the control path to every bastion, login node and management host, so compression behaviour is worth knowing about; but the record describes a weakness in a cryptographic/compression choice, not a code-execution or auth bypass, and gives no concrete exploitation scenario beyond the paper. Keep expectations at that level.

Who can reach it

Network, unauthenticated, but requires the ability to observe SSH traffic and high attack complexity per the CVSS vector. Affects sessions where compression is negotiated, on both the client (ssh) and server (sshd) side.

What to do

Fixed in OpenSSH 10.6 per the release notes. Upgrade the OpenSSH packages on login nodes, bastions and management hosts and restart sshd - existing sessions survive a restart, so this is a daemon restart rather than a reboot. As an interim measure, disabling compression (Compression no in sshd_config, -o Compression=no for clients) removes the path the finding depends on.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.