Import OpeSSH-10.6 (previous was 10.5)
OpenSSH 10.6 was released on 2026-10-06. It is available from the
mirrors listed at https://www.openssh.com/.
OpenSSH is a 100% complete SSH protocol 2.0 implementation and
includes sftp client and server support.
Recently the OpenSSH team have received a large number of security
bug reports, many of which are findings from AI models or made with
AI assistance. While many AI reports are determined not to have
security impact when considered in the context of a realistic
threat model, we very much welcome these reports, especially when
combined with human triage, analysis, test-cases and particularly
when accompanied by proposed fixes.
** We have seen a number of cases where a security bug identified
** by AI tools is subsequently independently discovered by a
** different researcher. This suggests that adversaries who do not
** report bugs to OSS projects are likely to be able to discover
[334 lines not shown]
usr/sbin/wgconfig: Increase ioctl buffer to 16384
Previously, the buffer used for ioctl was 4096. This worked for wg0
configured for 7 hosts, but failed for 8, surely because the proplist
to be returned was too big. This is malloced and only in use for the
duration of wgconfig, and thus of little consequence.
One could improve this by doubling the allocation every failure and
looping, or changing the kernel to report a needed length, but this
change should help a lot of people.
httpd(8): Don't set the PWD environment for CGIs, just the actual
working directory. This was based on a misunderstanding on my part.
PR bin/58713 httpd: CGIs have wrong cwd
aarch64: fix HPFAR_EL2_FIPA defines for various configurations
HPFAR_EL2_FIPA is 36bits long when FEAT_D128 and FEAT_LPA aren't
implemented, i.e. HPFAR_EL2[39:4]
Add HPFAR_EL2_FIPA_LPA for when FEAT_D128 is not implemented and
FEAT_LPA is.
Provide HPFAR_EL2_FIPA_{D128_,LPA_,}BITS for the Faulting Intermediate
Physical Address.
Remove HPFAR_EL2_FIPA_BITSHIFT
httpd(8): Per RFC 3875, set the PWD of child CGI processes to the
location of the script that is being run.
Right now this only works with the -c option (where previously PWD would
have been unset in the child), processes invoked with -C already got a
PWD, and the wrapper script can also handle setting it to something
sensible.
"looks good" mrg
PR bin/58713 httpd: CGIs have wrong cwd
PR kern/60601 - Avoid 32 bit wraparound on ILP32 hosts
In tmpfs_bytes_max calculate avail_mem using 64 bit calculations,
rather than one small piece being 32 bit only (and subject to
simple overflow, entirely within reasonable values).
Reported and diagnosed by Hashimoto Kenichi in PR kern/60601
XXX - pullup -11 -10 (in a week or two).
kk_KZ.PT154 locale: Add missing toupper/tolower mappings.
This was missing a tolower mapping (MAPLOWER) from the lower case
(ASCII) letters into themselves (which is required to work), and worse
was also missing a toupper mapping (MAPUPPER) from the lower case (ASCII)
letters into their upper case equivalents.
Whether the actual (non ASCII) letter upper/lower mappings are all
correct, I am not sure, but I very much doubt it.
Detected and reported by RVP@ in:
https://mail-index.netbsd.org/tech-userlevel/2026/08/15/msg015003.html
bsd.own.mk: Respect USE_FORT even if defined after bsd.own.mk.
Using (a chain of logic that boils down to)
.if ${USE_FORT:Uno} != "no"
CPPFLAGS+= -D_FORTIFY_SOURCE=2
.endif
expands USE_FORT eagerly, so if USE_FORT was not already defined before
including <bsd.own.mk>, it's too late after.
Using (a chain of logic that boils down to)
CPPFLAGS+= ${${USE_FORT:Uno} != "no":?-D_FORTIFY_SOURCE=2:}
expands USE_FORT lazily, so it's only when CPPFLAGS itself is expanded
-- usually in a recipe, after all variable assignments, prerequisite
lists, and .directives have been processed -- that USE_FORT is
expanded.
[9 lines not shown]
ssp.h: Stop creating references to useless __ssp_protected_* symbols.
The ssp wrappers are useful _only_ when they are actually used for
inline function call expansion; if the function is used for anything
else like a function pointer, only the underlying library symbol
should be used.
To pacify linker complaints about spurious references to
__ssp_protected_getcwd/read/readlink, we added equally spurious
definitions of those symbols to libc without understanding why; it
turns out it only happened because the ssp wrappers declared, e.g.:
extern inline read(...) __RENAME(__ssp_protected_read);
extern inline read(...) { <ssp check>; return __ssp_real_read(...); }
The declaration with __RENAME caused the compiler to generate
references, required by the linker to be resolved, to the symbol
`__ssp_protected_read' when compiling code that takes the address of
the function read() to pass around a function pointer. Instead, the
[15 lines not shown]
zaurus: MOve COPTS="-Os" from INSTALL to GENERIC.
INSTALL includes GENERIC, so no change to INSTALL. But the reason
for -Os (a size limitation of the bootloader, checked at build-time)
appears to apply just as well to any kernel, not just INSTALL, and
the recent change to flip on -ftrivial-auto-var-init bumped GENERIC
over the limit too:
Checking kernel size...
Fatal: kernel size must be less than 5MB.
Fatal: kernel size: 5247920, max kernel size: 5242880
--- netbsd ---
*** Failed target: netbsd
*** In directory: /home/builds/ab/HEAD/zaurus/20261006081837Z-obj/home/source/ab/HEAD/src/sys/arch/zaurus/compile/GENERIC
Setting COPTS="-Os" both tells the compiler to make smaller code, and
turns off the -ftrivial-auto-var-init logic in Makefile.kern.inc,
which with any luck should help fix the zaurus build.
[2 lines not shown]
mips: declare SPL stub functions in intr.h
Move the .stub section attributes for the MIPS SPL functions from
spl_stubs.c to intr.h, and add the splcheck declaration with __noubsan.
sys: Disable -ftrivial-auto-var-init if -Os is in play.
This should help avoid the code expansion that broke the zaurus and
ews4800mips builds.
PR kern/60839: use -ftrivial-auto-var-init