This bug was fixed in the package openssh-gssapi - 1:10.5p1-1ubuntu1
---------------
openssh-gssapi (1:10.5p1-1ubuntu1) stonking; urgency=medium
* Merge with Debian unstable (LP: #2166081). Remaining changes:
- d/rules, d/control: don't build with libwtmp, as it's in universe
* Added changes from src:openssh ubuntu delta:
- debian/tests/systemd-socket-activation: Add autopkgtest for systemd socket
activation functionality.
- d/t/sshd-socket-generator: add dep8 test for sshd-socket-generator
- d/t/control: add breaks-testbed restriction to tests
- d/t/control: install gssapi variants of the openssh packages
- d/tests: do not fail when $HOME/.ssh exists
- ssh.socket: adjust unit for socket activation by default
- debian/openssh-server-gssapi.postinst: restart whichever systemd unit is
enabled
- d/openssh-server-gssapi.links: add full sshd.service -> ssh.service
alias (LP #2087949)
- d/t/password-auth-no-pam: create /run/sshd for the custom test
service (LP: #2166924)
- debian/rules: modify dh_installsystemd invocations for
socket-activated sshd
- debian/.gitignore: drop file
- d/p/systemd-socket-activation.patch:
+ Fix sshd re-execution behavior when socket activation is used
+ Adapt sshd-session and sshd-auth for systemd socket activation
+ Allow AF_VSOCK sockets
- debian/patches: Immediately report interactive instructions to PAM clients
- debian/control: Build-Depends: systemd-dev
- d/p/sshd-socket-generator.patch: add generator for socket activation
- debian/openssh-server-gssapi.install: install sshd-socket-generator
- debian/rules: explicitly enable LTO
- d/p/test-set-UsePAM-no-on-some-tests.patch: set UsePAM=no for some tests
- document /etc/ssh/sshd_config.d/*.conf better in sshd_config
(LP #2088207)
- test: workaround test failure caused by uutils dd (LP #2125943)
- d/p/lp-2150273-openssh-pam-upn: Fix PAM user mismatch with
alternative UPN suffixes by comparing account UIDs instead of
username strings (LP #2150273)
- debian/openssh-server-gssapi.ucf-md5sum: update for Ubuntu delta
openssh-gssapi (1:10.5p1-1) unstable; urgency=medium
* password-auth-no-pam: Run test daemon via systemd.
* New upstream release (closes: #1144192):
- CVE-2026-73281: ssh-agent(1): fix an interaction between agent locking
and the [email protected] extension that is used to identify
forwarded agents. These binding requests were refused when the agent
was locked, with the result that operations that were intended to be
limited to local use only could be performed remotely, including the
ability to add PKCS#11 tokens and make use of keys that had
destination restrictions applied.
- CVE-2026-73282: ssh(1): avoid potential realloc use-after-free in the
client if a remote forwarding is added via the local session
multiplexing socket while a remote forwarding open request is pending
with the server.
- CVE-2026-73283: sshd(8): make the authorized_keys "restrict" keyword
apply correctly to tunnel forwarding too (which is administratively
disabled by default).
- ssh-keygen(1): add ability to set or clear the touch-required and
verify-required flags on FIDO private keys when resetting a private
key's passphrase.
- ssh(1): tweak ordering of certificates tried during pubkey
authentication to prefer FIDO keys that do not require user presence
(touch) first, and FIDO keys that require user verification via PIN or
biometrics last. This effectively tries low-friction authenticators
before higher friction ones.
- ssh(1): add a "ssh -Z user@host" mode that prints the keys that will
be tried for public key authentication in the order that they will be
used.
- sshd(8) use setproctitle(3) to identify sshd-session when it's acting
as a post-authentication monitor.
- ssh-keyscan(1): make reading the server banner a non-blocking
operation to prevent a stuck server from blocking a many-host keyscan
from proceeding.
- sshd(8): use sshpkt_fatal() instead of plain fatal() for errors in the
packet code as this provides context of the failing peer (address,
port, user, etc).
- sshd(8): when signing hostkey proofs for a client UpdateHostKeys
request, allow each hostkey to perform at most one signature
operation.
- ssh-keygen(1): pass back errors from ed25519 key generation, which
theoretically can fail.
- sshd(8): move check of public key type against allowed algorithms to
before parsing of the key sent by the peer. This removes at least some
key parsing and verification paths from the pre-auth attack surface.
- ssh-keygen(1): fix double frees (impossible to reach outside of a test
harness), and also use freezero where possible.
- sshd(8): fix ChannelTimeout and RekeyLimit not being applied in
sshd_config Match blocks.
- sshd(8): in sshd config dump mode, write all directives in mixed case
for consistency.
- sshd(8): re-allow PAMServiceName inside a Match block, which was
incorrectly disabled during a refactoring in openssh-10.4.
-- Andreas Hasenack <[email protected]> Wed, 02 Sep 2026
16:42:02 -0300
** Changed in: openssh-gssapi (Ubuntu)
Status: In Progress => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2166081
Title:
Fourth openssh merge from debian for stonking
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/2166081/+subscriptions
--
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs