OpenSSH 9.2 released
This release contains fixes for two security problems and a memory safety problem. The memory safety problem is not believed to be exploitable, but we report most network-reachable memory faults as security bugs.
Update
In the official site:
-
OpenSSH 9.6 was released on 2023-12-18.
Once again, we would like to thank the OpenSSH community for their continued support of the project, especially those who contributed code or patches, reported bugs, tested snapshots or donated to the project. More information on donations may be found at: https://www.openssh.com/donations.html
LWN:
-
OpenSSH 9.6 released
OpenSSH 9.6 has been released. It includes some minor improvements and a fix for the so-called Terrapin attack.
One more, mailing lists:
-
OpenSSH 9.6 released!
The complete release notes may be found here: https://www.openssh.com/releasenotes.html#9.6.
In the media:
-
SSH shaken, not stirred by Terrapin vulnerability
The technique, dubbed the Terrapin Attack, is described in a technical write-up shared this week by Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk, who are computer scientists at Germany's Ruhr University Bochum. In October, after discovering the vulnerability, they privately disclosed the details to SSH client and server developers to address. Now it's all public with patches and info coming out.