CVSROOT: /cvs
Module name: src
Changes by: [email protected] 2026/09/21 22:38:09
Modified files:
usr.bin/ssh : packet.c
Log message:
Disable LZ77 dictionary coder to avoid a potential side-channel leak
A chosen-plaintext attack method exists which makes use of
dictionary-based compression to recover secrets from one channel by
interacting with the SSH session's shared compression dictionary through
another channel.
Attacker-controlled input can recognizably reflect into the total length
of transmitted ciphertexts by virtue of LZ77 replacing repeated strings
with back-references into the SSH session's encoder search buffer,
which is shared across all channels. For this reason, the documentation
already recommended against enabling compression for connections that
share trusted and untrusted traffic.
As an extra precaution, use only Huffman coding when compressing
plaintexts, as this algorithm does not use a dictionary. But, this
results in a reduction of compression effectiveness.
Inspired by "Crossing the Streams: SSH Plaintext Recovery via a Common
Compression Context in Multiplexed Channels." by Fabian Bäumer and
Marcus Brinkmann, preprint https://arxiv.org/abs/2609.07709 (2026)
OK djm@ dtucker@