OpenSSH has released version 10.4 with eight security fixes affecting both client and server components, including sftp, scp, sshd, ssh, ssh-agent, and cryptographic verification logic. The update addresses path traversal-style and file redirection issues that could let a malicious server write files outside intended locations, a pre-authentication denial-of-service condition in sshd, a client-side use-after-free bug, and gaps in authentication delay enforcement. The release also replaces the wildcard matcher with an NFA-based implementation to remove exponential worst-case behavior.
The release introduces experimental support for a composite post-quantum signature scheme combining ML-DSA 44 with Ed25519, available only when explicitly enabled and configured. OpenSSH also hardened protocol handling by disconnecting peers that send non-KEX messages during post-authentication rekeying and made seccomp sandbox initialization failures fatal on Linux. Maintainers warned that some changes may break existing deployments, including mixed-case output from sshd -G, stricter transport-layer behavior, and the new sandbox failure handling.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
OpenSSH released version 10.4 with eight security fixes affecting components including sftp, scp, sshd, ssh, and ssh-agent, addressing issues such as malicious-server file write and traversal problems, a pre-authentication denial of service, and a client-side use-after-free bug. The release also introduced experimental composite post-quantum signatures using ML-DSA 44 with Ed25519 and protocol hardening changes including stricter post-authentication rekey handling and fatal seccomp sandbox initialization failures on Linux.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcelinuxsecurity.com
Open sourcemarc.info
Open sourceopenwall.com
Open sourceopennet.me
Open sourceopennet.ru
Open sourcelists.mindrot.org
Open sourcecdn.openbsd.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.