public inbox for development@lists.ipfire.org
 help / color / mirror / Atom feed
From: Adolf Belka <adolf.belka@ipfire.org>
To: development@lists.ipfire.org
Cc: Adolf Belka <adolf.belka@ipfire.org>
Subject: [PATCH] openssh: Update to version 10.5p1
Date: Thu, 13 Aug 2026 15:39:37 +0200	[thread overview]
Message-ID: <20260813133942.2669472-8-adolf.belka@ipfire.org> (raw)
In-Reply-To: <20260813133942.2669472-1-adolf.belka@ipfire.org>

- Update from version 10.4p1 to 10.5p1
- No change in rootfile
- Changelog
10.5p1
Potentially-incompatible changes
 * Portable OpenSSH now requires ECC (Elliptic Curve Cryptography)
   support in libcrypto, including support for the NISTP521 curve.
   ECC is included in the default build configurations of all
   versions of all libcrypto implementations currently supported by
   OpenSSH, including LibreSSL, OpenSSL, BoringSSL and AWS LC.
   The --without-openssl build configuration is not affected.
Security
 * ssh-agent(1): fix an interaction between agent locking and the
   session-bind@openssh.com extension that is used to identify
   forwarded agents. These binding requests were refused when the
   agent was locked, with the result that operations that were
   intended to be limited to local use only could be performed
   remotely, including the ability to add PKCS#11 tokens and make
   use of keys that had destination restrictions applied.
   Reported by sn0x-sharma
 * ssh(1): avoid potential realloc use-after-free in the client if a
   remote forwarding is added via the local session multiplexing
   socket while a remote forwarding open request is pending with the
   server. Report and fix from Brian Mingus of Cognatory
 * sshd(8): make the authorized_keys "restrict" keyword apply
   correctly to tunnel forwarding too (which is administratively
   disabled by default). Reported by Erichen, Institute of Computing
   Technology, Chinese Academy of Sciences
New features
 * ssh-keygen(1): add ability to set or clear the touch-required and
   verify-required flags on FIDO private keys when resetting a
   private key's passphrase.
 * ssh(1): tweak ordering of certificates tried during pubkey
    authentication to prefer FIDO keys that do not require user
    presence (touch) first, and FIDO keys that require user
    verification via PIN or biometrics last. This effectively tries
    low-friction authenticators before higher friction ones.
 * ssh(1): add a "ssh -Z user@host" mode that prints the keys that
   will be tried for public key authentication in the order that
   they will be used.
 * sshd(8) use setproctitle(3) to identify sshd-session when its
   acting as a post-authentication monitor.
Bugfixes
 * ssh-keyscan(1): make reading the server banner a non-blocking
   operation to prevent a stuck server from blocking a many-host
   keyscan from proceeding.
 * sshd(8): use sshpkt_fatal() instead of plain fatal() for errors
   in the packet code as this provides context of the failing peer
   (address, port, user, etc).
 * sshd(8): when signing hostkey proofs for a client UpdateHostKeys
   request, allow each hostkey to perform at most one signature
   operation.
 * sshd(8) fix GSSAPI option names, that were broken during a
   servconf.c refactoring in openssh-10.4; bz3974.
 * ssh-keygen(1): pass back errors from ed25519 key generation, which
   theoretically can fail. GHPR702.
 * sshd(8): move check of public key type against allowed algorithms
   to before parsing of the key sent by the peer. This removes at
   least some key parsing and verification paths from the pre-auth
   attack surface. Suggested by Christopher Paul Rohlf of Anthropic.
 * ssh-keygen(1): fix double frees (impossible to reach outside of a
   test harness), and also use freezero where possible. From
   Christopher Paul Rohlf at Anthropic.
 * sshd(8): fix ChannelTimeout and RekeyLimit not being applied in
   sshd_config Match blocks.
 * sshd(8): in sshd config dump mode, write all directives in mixed
   case for consistency
Portability
 * sshd(8): re-allow PAMServiceName inside a Match block, which
   was incorrectly disabled during a refactoring in openssh-10.4.
   bz3987

Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
 lfs/openssh | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/lfs/openssh b/lfs/openssh
index e7acb2058..a792df365 100644
--- a/lfs/openssh
+++ b/lfs/openssh
@@ -24,7 +24,7 @@
 
 include Config
 
-VER        = 10.4p1
+VER        = 10.5p1
 
 THISAPP    = openssh-$(VER)
 DL_FILE    = $(THISAPP).tar.gz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
 
 $(DL_FILE) = $(DL_FROM)/$(DL_FILE)
 
-$(DL_FILE)_BLAKE2 = 3051a345fd24333708277a1de781deca9094dd07cc55e613e93715b1266d80d59043bf5cdb2282d02c797cb9446916020e70fbd4c7a2470da7ab98eb612f6b74
+$(DL_FILE)_BLAKE2 = 8e8be4e4aff6b5f16e19f85b994fcc9b7679021cf639fad4323dc15f6bc0041b45370024a5f51065e2a92d965428cf3787323957f2c41f4d27fc1146dc3690cf
 
 install : $(TARGET)
 
-- 
2.55.0



  parent reply	other threads:[~2026-08-13 13:40 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-13 13:39 [PATCH] aprutil: Update to version 1.6.5 Adolf Belka
2026-08-13 13:39 ` [PATCH] core205: Ship aprutil Adolf Belka
2026-08-13 13:39 ` [PATCH] core205: Ship openssh Adolf Belka
2026-08-13 13:39 ` [PATCH] core205: Ship procps Adolf Belka
2026-08-13 13:39 ` [PATCH] core205: Ship wpa_supplicant Adolf Belka
2026-08-13 13:39 ` [PATCH] fontconfig: Update to version 2.18.3 Adolf Belka
2026-08-13 13:39 ` [PATCH] libffi: Update to version 3.8.0 Adolf Belka
2026-08-13 13:39 ` Adolf Belka [this message]
2026-08-13 13:39 ` [PATCH] p11-kit: Update to version 0.26.5 Adolf Belka
2026-08-13 13:39 ` [PATCH] postfix: Update to version 3.11.6 Adolf Belka
2026-08-13 13:39 ` [PATCH] procps: Update to version 4.0.7 Adolf Belka
2026-08-13 13:39 ` [PATCH] rsync: Update to version 3.5.0 Adolf Belka
2026-08-13 13:39 ` [PATCH] wpa_supplicant: Update to version 2.12 Adolf Belka

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260813133942.2669472-8-adolf.belka@ipfire.org \
    --to=adolf.belka@ipfire.org \
    --cc=development@lists.ipfire.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox