./security/openssh, Open Source Secure shell client and server (remote login program)

[ Image CVSweb ] [ Image Homepage ] [ Image RSS ] [ Image Required by ]


Branch: CURRENT, Version: 10.5p1nb2, Package name: openssh-10.5p1nb2, Maintainer: pkgsrc-users

OpenSSH is based on the last free version of Tatu Ylonen's SSH with
all patent-encumbered algorithms removed (to external libraries), all
known security bugs fixed, new features reintroduced and many other
clean-ups. More information about SSH itself can be found in the file
README.Ylonen. OpenSSH has been created by Aaron Campbell, Bob Beck,
Markus Friedl, Niels Provos, Theo de Raadt, and Dug Song.

This port consists of the re-introduction of autoconf support, PAM
support (for Linux and Solaris), EGD[1] support, SOCKS support (using
the Dante [6] libraries and replacements for OpenBSD library functions
that are (regrettably) absent from other unices. This port has been
best tested on Linux, Solaris, HPUX, NetBSD and Irix. Support for AIX,
SCO, NeXT and other Unices is underway. This version actively tracks
changes in the OpenBSD CVS repository.

MESSAGE.Interix [+/-]
MESSAGE.pam [+/-]
MESSAGE.urandom [+/-]

Required to run:
[security/openssl]

Required to build:
[pkgtools/cwrappers]

Package options: editline, fido, openssl, pam

Master sites: (Expand)

Filesize: 2278.964 KB

Version history: (Expand)


CVS history: (Expand)


   2026-10-05 20:48:24 by Havard Eidnes | Files touched by this commit (1)
Log message:
security/openssh: sigh, remove debug and a false turn.
   2026-10-05 20:08:15 by Havard Eidnes | Files touched by this commit (3)
Log message:
security/openssh: pull in fix from the main NetBSD source tree for PR#60563.

This tests for vwrite() instead of read() in atomicio.c, so
as to avoid the renaming shenanigans done by SSP of read().

Thanks to riastradh@ for pointing me in the right direction.

Bump PKGREVISION.
   2026-09-22 10:06:07 by Thomas Klausner | Files touched by this commit (1)
Log message:
openssh: remove CFLAGS -g
   2026-09-22 10:03:59 by Havard Eidnes | Files touched by this commit (4)
Log message:
security/openssh: remove no-longer-needed BROKEN_READ_COMPARISON code.

This mirrors upstream change:

  https://github.com/openssh/openssh-portable/commit/a765b86d

ref. mailing list thread at

  https://lists.mindrot.org/pipermail/openssh-unix-dev/2026-September/042758.html

Bump PKGREVISION.
   2026-08-11 09:16:40 by Thomas Klausner | Files touched by this commit (2) | Package updated
Log message:
openssh: update to 10.5p1.

Changes since OpenSSH 10.4
==========================

This release contains a number of security fixes and small bugfixes.

Security
========

 * ssh-agent(1): fix an interaction between agent locking and the
   session-bind@openssh.com extension that is used to identify
   forwarded agents. These binding requests were refused when the
   agent was locked, with the result that operations that were
   intended to be limited to local use only could be performed
   remotely, including the ability to add PKCS#11 tokens and make
   use of keys that had destination restrictions applied.
   Reported by sn0x-sharma

 * ssh(1): avoid potential realloc use-after-free in the client if a
   remote forwarding is added via the local session multiplexing
   socket while a remote forwarding open request is pending with the
   server. Report and fix from Brian Mingus of Cognatory

 * sshd(8): make the authorized_keys "restrict" keyword apply
   correctly to tunnel forwarding too (which is administratively
   disabled by default). Reported by Erichen, Institute of Computing
   Technology, Chinese Academy of Sciences

New features
------------

 * ssh-keygen(1): add ability to set or clear the touch-required and
   verify-required flags on FIDO private keys when resetting a
   private key's passphrase.

 * ssh(1): tweak ordering of certificates tried during pubkey
    authentication to prefer FIDO keys that do not require user
    presence (touch) first, and FIDO keys that require user
    verification via PIN or biometrics last. This effectively tries
    low-friction authenticators before higher friction ones.

 * ssh(1): add a "ssh -Z user@host" mode that prints the keys that
   will be tried for public key authentication in the order that
   they will be used.

 * sshd(8) use setproctitle(3) to identify sshd-session when its
   acting as a post-authentication monitor.

Bugfixes
--------

 * ssh-keyscan(1): make reading the server banner a non-blocking
   operation to prevent a stuck server from blocking a many-host
   keyscan from proceeding.

 * sshd(8): use sshpkt_fatal() instead of plain fatal() for errors
   in the packet code as this provides context of the failing peer
   (address, port, user, etc).

 * sshd(8): when signing hostkey proofs for a client UpdateHostKeys
   request, allow each hostkey to perform at most one signature
   operation.

 * sshd(8) fix GSSAPI option names, that were broken during a
   servconf.c refactoring in openssh-10.4; bz3974.

 * ssh-keygen(1): pass back errors from ed25519 key generation, which
   theoretically can fail. GHPR702.

 * sshd(8): move check of public key type against allowed algorithms
   to before parsing of the key sent by the peer. This removes at
   least some key parsing and verification paths from the pre-auth
   attack surface. Suggested by Christopher Paul Rohlf of Anthropic.

 * ssh-keygen(1): fix double frees (impossible to reach outside of a
   test harness), and also use freezero where possible. From
   Christopher Paul Rohlf at Anthropic.

 * sshd(8): fix ChannelTimeout and RekeyLimit not being applied in
   sshd_config Match blocks.

 * sshd(8): in sshd config dump mode, write all directives in mixed
   case for consistency

Portability
-----------

 * sshd(8): re-allow PAMServiceName inside a Match block, which
   was incorrectly disabled during a refactoring in openssh-10.4.
   bz3987
   2026-08-03 15:12:34 by Thomas Klausner | Files touched by this commit (98)
Log message:
mk: switch the default for PATCH_DIST_STRIP from -p0 to -p1

adapt packages that didn't set PATCH_DIST_STRIP to use -p0, and
remove the -p1 lines
   2026-07-06 18:31:47 by Thomas Klausner | Files touched by this commit (2) | Package updated
Log message:
openssh: update to 10.4p1.

Changes since OpenSSH 10.3
==========================

This release contains a number of security fixes as well as general
bugfixes and a couple of new features.

Security
========

 * sftp(1): when downloading files on the command-line using
   "sftp host:/path .", a malicious server could cause the file to
   be downloaded to an unexpected location. This issue was identified
   by the Swival Security Scanner.

 * scp(1): when copying files between two remote destinations, do
   not allow a malicious server to write files to the parent
   directory of the intended target directory.  This issue was
   identified by the Swival Security Scanner.

 * sshd(8): when using the "internal-sftp" SFTP server implementation
   (this is not the default), long command lines were previously
   truncated silently after the 9th argument. If a security-relevant
   option was in the 10th or later position, it would be discarded.
   Reported by Steve Caffrey.

 * sshd(8): add a documentation note to mention that the
   GSSAPIStrictAcceptorCheck option is ineffective when the server
   is joined to a Windows Active Directory. Reported by Yarin Aharoni
   of Safebreach.

 * sshd(8): DisableForwarding=yes didn't override PermitTunnel=yes
   as it was documented to do. Note that PermitTunnel is not enabled
   by default. Reported independently by Huzaifa Sidhpurwala of
   Redhat and Marko Jevtic.

 * sshd(8): avoid a potential pre-authentication denial of service
   when GSSAPIAuthentication was enabled (this feature is off by
   default). This was not mitigated by MaxAuthTries, but would be
   penalised by PerSourcePenalties. This was reported by Manfred
   Kaiser of the milCERT AT (Austrian Ministry of Defence).

 * sshd(8): fix a number of cases where the minimum authentication
   delay was not being enforced. Reported by the Orange Cyberdefense
   Vulnerability Team.

 * ssh(1): fix a possible client-side use-after-free if the server
   changes its host key during a key reexchange. This was reported by
   Zhenpeng (Leo) Lin of Depthfirst.

New features
------------

 * All: add experimental support for a composite post-quantum
   signature scheme that combines ML-DSA 44 and Ed25519 as specified
   in draft-miller-sshm-mldsa44-ed25519-composite-sigs.

   This scheme is not enabled by default. To use it, you'll need
   to add it to HostKeyAlgorithms, PubkeyAcceptedAlgorithms, etc.
   Keys may be generated using "ssh-keygen -t mldsa44-ed25519".

 * ssh(1), sshd(8): replace the wildcard pattern matcher with an
   implementation based on an NFA. This avoids exponential worst-case
   behaviour for the old implementation.

Bugfixes
--------

 * ssh-agent(1): fix incorrect reply to "query" SSH_AGENTC_EXTENSION
   requests. bz3967

 * sshd(8): avoid sending observably different messages for valid vs
   invalid users in GSSAPIAuthentication (disabled by default).

 * ssh(1), sshd(8): fix several bugs that incorrectly
   classified bulk traffic as interactive. bz3972, bz3958

 * ssh-keygen(1), ssh-add(1): skip unsupported key types when
   downloading resident keys from a FIDO token. Previously, downloads
   would abort when one was encountered. GHPR657

 * ssh(1): fix a potential use-after-free on an error path if
   cipher_init() fails.

 * sshd(8): perform stricter encoding and validation of transport
   state passed between sshd privilege separation subprocesses. This
   somewhat further hardens the server against attacks on sshd-auth
   or sshd-session subprocesses.

 * ssh-agent(1): avoid possible runtime denial of service by
   enforcing some limits on the length of usernames in key use
   constraints.

 * sftp(1): fix two separate one-byte out-of-bounds reads, in
   SSH2_FXP_REALPATH and batch command processing.

 * sftp-server(8): disallow use of the copy-data extension to read
   and write to the same inode simultaneously.

 * ssh(1), sshd(8): avoid strlen(NULL) crash if an X11 channel was
   created before the x11-req SSH_MSG_CHANNEL_REQUEST was sent.
   GHPR679

 * sftp(1), scp(1): avoid a situation where sftp_download() could get
   stuck in a loop if a broken server repeatedly returned zero length
   while reading a file.

 * ssh(1): avoid leaking DNS0x20 case-randomised names into names
   canonicalised using CanonicalizePermittedCNAMEs. bz3966

 * sftp-server(8): avoid truncation of pathnames passed to lstat()
   during SSH_FXP_REALPATH handling on systems where PATH_MAX is not
   the actual max. GHPR688

 * ssh(1), sshd(8): correct arming of poll(2) event masks for some
   socket-type channels. GHPR660

 * sshd(8): major refactor of sshd_config parsing and management
   code, to allow for more exact serialisation/deserialisation across
   privilege separation boundaries.

 * ssh-add(1): open connection to the agent only after getopt()
   processing has completed, to give options like "-v" a chance to
   display debug information about this operation.

 * crypto code: fix bounds checking when signing messages of length
   greater than will fit in a size_t. In OpenSSH, message sizes are
   bounded by SSHBUF_SIZE_MAX so this was unreachable.

 * crypto code: add signature malleability and pubkey validity checks
   to ed25519 verification. SSH doesn't depend on these properties

 * crypto code: fix ECDSA order check for curves with cofactor != 1.
   All supported EC curves have cofactor 1, so this was
   unreachable.

 * sshd(8): differentiate between execution failures and a subsystem
   that was not found when logging why a subsystem failed to start.
   GHPR637

 * All: use safer idioms for timegm(3) and mktime(3) error detection.

 * ssh(1), sshd(8): avoid accepting invalid cipher or MAC lists in
   config files or command-line arguments. This could cause runtime
   failures later.

 * ssh(1): fix NULL deref crash during pubkey auth when using a PEM
   style private key with no corresponding .pub key adjacent to it.

 * sshd(8): don't print an error message when trying to load a host
   private key when PKCS#11 keys are in use, as these don't need the
   private half on the filesystem. GHPR664

 * All: don't use deprecated ERR_load_crypto_strings(). GHPR650

 * ssh(1): properly report errors during configuration default
   setting. GHPR649

 * ssh(1): use correct directive name (Match instead of Host) in
   error message. bz3968

 * sftp(1): fix "ls -ln" which was not correctly showing numeric
   UID/GIDs but rather user and group names. bz3953

 * sshd(8): avoid possible NULL dereference if an allocation fails
   during config parsing. bz3948

 * All: fix ineffective guards against loading overly large public
   keys in several places. bz3969 and bz3970

 * sftp(1): ensure file descriptors used by sftp to communicate to
   its ssh(1) subprocess don't leak into executed subprocesses (e.g.
   via "!"). GHPR693

Portability
-----------

 * Sync fmt_scaled.c with OpenBSD upstream, picking up an exactness
   fix for large exponents (GHPR671)

 * sshd(8): remove duplicate sandbox entry for clock_gettime64.

 * ssh(1), sshd(8): use correct IPTOS_DSCP_VA value if not provided
   by the system headers.

 * Sync getrrsetbyname.c with OpenBSD upstream, picking up robustness
   fixes.

 * Disable replacements in openbsd-compat for strvisx(3) and
   stravis(3), as these are unused in OpenSSH

 * Avoid fortify warnings on Android bz3954

 * Fix a number of memory leaks on error paths in the portability
   code. GHPR681

 * Revise the README.privsep documentation to reflect sshd's recent
   switch to a multi-binary model.
   2026-04-02 12:32:43 by Thomas Klausner | Files touched by this commit (2) | Package updated
Log message:
openssh: update to 10.3p1.

Potentially-incompatible changes
--------------------------------

 * ssh(1), sshd(8): remove bug compatibility for implementations
   that don't support rekeying. If such an implementation tries to
   interoperate with OpenSSH, it will now eventually fail when the
   transport needs rekeying.

 * sshd(8): prior to this release, a certificate that had an empty
   principals section would be treated as matching any principal
   (i.e. as a wildcard) when used via authorized_keys principals=""
   option. This was intentional, but created a surprising and
   potentially risky situation if a CA accidentally issued a
   certificate with an empty principals section: instead of being
   useless as one might expect, it could be used to authenticate as
   any user who trusted the CA via authorized_keys. [Note that this
   condition did not apply to CAs trusted via the sshd_config(5)
   TrustedUserCAKeys option.]

   This release treats an empty principals section as never matching
   any principal, and also fixes interpretation of wildcard
   characters in certificate principals. Now they are consistently
   implemented for host certificates and not supported for user
   certificates.

 * ssh(1): the -J and equivalent -oProxyJump="..." options now
   validate user and host names for ProxyJump/-J options passed
   via the command-line (no such validation is performed for this
   option in configuration files). This prevents shell injection in
   situations where these were directly exposed to adversarial
   input, which would have been a terrible idea to begin with.
   Reported by rabbit.

Changes since OpenSSH 10.2
==========================

This release contains some relatively minor security fixes as well
as a number of feature improvements and general bugfixes.

Security
========

 * ssh(1): validation of shell metacharacters in user names supplied
   on the command-line was performed too late to prevent some
   situations where they could be expanded from %-tokens in
   ssh_config. For certain configurations, such as those that use a
   "%u" token in a "Match exec" block, an attacker who can \ 
control
   the user name passed to ssh(1) could potentially execute arbitrary
   shell commands.  Reported by Florian Kohnhäuser.

   We continue to recommend against directly exposing ssh(1) and
   other tools' command-lines to untrusted input. Mitigations such
   as this can not be absolute given the variety of shells and user
   configurations in use.

 * sshd(8): when matching an authorized_keys principals="" option
   against a list of principals in a certificate, an incorrect
   algorithm was used that could allow inappropriate matching in
   cases where a principal name in the certificate contains a
   comma character. Exploitation of the condition requires an
   authorized_keys principals="" option that lists more than one
   principal *and* a CA that will issue a certificate that encodes
   more than one of these principal names separated by a comma
   (typical CAs stronly constrain which principal names they will
   place in a certificate). This condition only applies to user-
   trusted CA keys in authorized_keys, the main certificate
   authentication path (TrustedUserCAKeys/AuthorizedPrincipalsFile)
   is not affected. Reported by Vladimir Tokarev.

 * scp(1): when downloading files as root in legacy (-O) mode and
   without the -p (preserve modes) flag set, scp did not clear
   setuid/setgid bits from downloaded files as one might typically
   expect. This bug dates back to the original Berkeley rcp program.
   Reported by Christos Papakonstantinou of Cantina and Spearbit.

 * sshd(8): fix incomplete application of PubkeyAcceptedAlgorithms
   and HostbasedAcceptedAlgorithms with regard to ECDSA keys.
   Previously if one of these directives contains any ECDSA algorithm
   name (say "ecdsa-sha2-nistp384"), then any other ECDSA algorithm
   would be accepted in its place regardless of whether it was
   listed or not.  Reported by Christos Papakonstantinou of Cantina
   and Spearbit.

 * ssh(1): connection multiplexing confirmation (requested using
   "ControlMaster ask/autoask") was not being tested for proxy mode
   multiplexing sessions (i.e. "ssh -O proxy ..."). Reported by
   Michalis Vasileiadis.

New features
------------

 * ssh(1), sshd(8): support IANA-assigned codepoints for SSH agent
   forwarding, as per draft-ietf-sshm-ssh-agent. Support for the new
   names is advertised via the EXT_INFO message. If a server offers
   support for the new names, then they are used preferentially.

   Support for the pre-standardisation "@openssh.com" extensions for
   agent forwarding remains supported.

 * ssh-agent(1): implement support for draft-ietf-sshm-ssh-agent
   "query" extension.

 * ssh-add(1): support querying the protocol extensions via the
   agent "query" extension with a new -Q flag.

 * ssh(1): support multiple files in a ssh_config RevokedHostKeys
   directive. bz3918

 * sshd(8): support multiple files in a sshd_config RevokedKeys
   directive bz3918

 * ssh(1): add a ~I escape option that shows information about the
   current SSH connection.

 * ssh(1): add an "ssh -Oconninfo user@host" multiplexing command
   that shows connection information, similar to the ~I escapechar.

 * ssh(1): add an "ssh -O channels user@host" multiplexing command to
   get a running mux process to show information about what channels
   are currently open.

 * sshd(8): add 'invaliduser' penalty to PerSourcePenalties, which is
   applied to login attempts for usernames that do not match real
   accounts. Defaults to 5s to match 'authfail' but allows
   administrators to block such attempts for longer if desired.

 * sshd(8): add a GSSAPIDelegateCredentials option for the server,
   controlling whether it accepts delegated credentials offered by
   the client.  This option mirrors the same option in ssh_config.
   GHPR614

 * ssh(1), sshd(8): support the VA DSCP codepoint in the IPQoS
   directive.

 * sshd(8): convert PerSourcePenalties to using floating point time,
   allowing penalties to be less than a second. This is useful if you
   need to penalise things you expect to occur at >=1 QPS.

 * ssh-keygen(1): support writing ED25519 keys in PKCS8 format.
   GHPR570

 * Support the ed25519 signature scheme via libcrypto.

Bugfixes
--------

 * sshd(8): make IPQoS first-match-wins in sshd_config, like other
   configuration directives. bz3924

 * sshd(8): fix potential crash when MaxStartups is using a single
   argument (i.e. not using the MaxStartps x:y:z form) to a value
   below 10. bz3941

 * sshd(8): fix a potential hang during key exchange if needed DH
   group values were missing from /etc/moduli.

 * ssh-agent(1): fix return values from extensions to be correct wrt
   draft-ietf-sshm-ssh-agent: extension requests should indicate
   failure using SSH_AGENT_EXTENSION_FAILURE rather than the generic
   SSH_AGENT_FAILURE error code. This allows the client to discern
   between "the request failed" and "the agent doesn't support this
   extension".

 * ssh(1): use fmprintf for showing challenge-response name and info
   to preserve UTF-8 characters where appropriate. Prompted by GitHub
   PR#452.

 * scp(1): when uploading a directory using sftp/sftp (e.g. during a
   recursive transfer), don't clobber the remote directory
   permissions unless either we created the directory during the
   transfer or the -p flag was set. bz3925

 * All: implement missing pieces of FIDO/webauthn signature support,
   mostly related to certificate handling and enable acceptance of this
   signature format by default.  bz3748 GHPR624 GHPR625

 * sshd_config(5): make it clear that DenyUsers/DenyGroups overrides
   AllowUsers/AllowGroups. Previously we specified the order in which
   the directives are processed but it was ambiguous as to what
   happened if both matched.

 * ssh(1): don't try to match certificates held in an agent to
   private keys. This matching is done to support certificates that
   were loaded without their private key material, but is
   unnecessary for agent-hosted certificate which always have
   private key material available in the agent. Worse, this matching
   would mess up the request sent to the agent in such a way as to
   break usage of these keys when the key usage was restricted in
   the agent.  bz3752

 * sftp(1): if editline has been switched to vi mode (i.e. via "bind
   -v" in .editrc), setup a keybinding so that command mode can be
   entered.

 * ssh(1), sshd(8): improve performance of keying the sntrup761 key
   agreement algorithm.

 * ssh(1), sshd(8): enforce maximum packet/block limit during
   pre-authentication phase.

 * sftp(1): don't misuse the sftp limits extension's open-handles
   field. This value is supposed to be the number of handles a
   server will allow to be opened and not a number of outstanding
   read/write requests that can be sent during an upload/download.

 * sshd(8): don't crash at connection time if the main sshd_config
   lacks any subsystem directive but one is defined in a Match block.
   bz3906

 * sshd_config(5): add a warning next to the ForceCommand directive
   that forcing a command doesn't automatically disable forwarding.

 * sshd_config(5): add a warning that TOKENS are replaced without
   filtering or escaping and that it's the administrator's
   responsibility to ensure they are used safely in context.

 * scp(1): correctly quote filenames in verbose output for local->
   local copies. bz3900

 * sshd(8): don't mess up the PerSourceNetBlockSize IPv6 mask if
   sscanf didn't decode it. GHPR598

 * ssh-add(1): when loading FIDO2 resident keys, set the comment to
   the FIDO application string. This matches the behaviour of
   ssh-keygen -K. GHPR608

 * sshd(8): don't strnvis() log messages that are going to be logged
   by sshd-auth via its parent sshd-session process, as the parent
   will also run them though strnvis(). Prevents double-escaping of
   non-printing characters in some log messages. bz3896

 * ssh-agent(1): escape SSH_AUTH_SOCK paths that are sent to the
   shell as setenv commands. Unbreaks ssh-agent for home directory
   paths that contain whitespace. bz3884

 * All: Remove unnecessary checks for ECDSA public key validity.

 * sshd(8): activate UnusedConnectionTimeout only after the last
   channel has closed. Previously UnusedConnectionTimeout could fire
   early after a ChannelTimeout. This was not a problem for the
   OpenSSH client because it terminates once all channels have
   closed but could cause problems for other clients (e.g. API
   clients) that do things differently.  bz3827

 * All: fix PKCS#11 key PIN entry problems introduced in
   openssh-10.1/10.2.  bz3879

 * scp(1): when using the SFTP protocol for transfers, fix implicit
   destination path selection when source path ends with "..". bz3871

 * sftp(1): when tab-completing a filename, ensure that the completed
   string does not end up mid-way through a multibyte character, as
   this will cause a fatal() later on. GHPR#587

 * ssh-keygen(1): fix crash at exit (visible via ssh-keygen -D) when
   multiple keys loaded.

 * scp(1)/sftp(1): correctly display bandwidths >2GBps in the
   progress meter.

Portability
-----------

 * sshd(8): fix condition intoduced in openssh 10.2p1 stable branch
   here a PAM module that changed the requested username between
   SSH_MSG_USERAUTH_REQUEST messages during authentication could
   confuse the PAM stack and let it proceed with a different
   understanding of the active username than the rest of sshd.
   Reported by Mike Damm.

 * sshd(8): immediately report interactive instructions to clients
   when using keyboard-interactive authentication with PAM. bz2876

 * sshd(8): fix duplicate PAM messages under some situations.

 * sshd(8): don't leak PAM handle on repeat invocations. bz3882

 * All: support linking libcrypto implementations (e.g. BoringSSL)
   that require libstdc++.

 * sshd(8): fix ut_type for btmp records, correctly using
   LOGIN_PROCESS and USER_PROCESS.

 * sshd(8): allow uname(3) in the seccomp sandbox. This is needed by
   zlib-ng on RISC-V platforms.

 * All: remove remaining OpenSSL_add_all_algorithms() calls.
   We already have OPENSSL_init_crypto() in the compat layer.
   Prompted by github PR#606

 * All: fix builds on older Mac OS wrt nfds_t.

 * mdoc2man: several improvements including better support for Dl
   and Ns inside Ic.