OpenSSH has released version 10.4 with eight security fixes affecting both client and server components, including sftp, scp, sshd, ssh, ssh-agent, and cryptographic verification logic. The update addresses path traversal-style and file redirection issues that could let a malicious server write files outside intended locations, a pre-authentication denial-of-service condition in sshd, a client-side use-after-free bug, and gaps in authentication delay enforcement. The release also replaces the wildcard matcher with an NFA-based implementation to remove exponential worst-case behavior.
The release introduces experimental support for a composite post-quantum signature scheme combining ML-DSA 44 with Ed25519, available only when explicitly enabled and configured. OpenSSH also hardened protocol handling by disconnecting peers that send non-KEX messages during post-authentication rekeying and made seccomp sandbox initialization failures fatal on Linux. Maintainers warned that some changes may break existing deployments, including mixed-case output from sshd -G, stricter transport-layer behavior, and the new sandbox failure handling.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
OpenSSH released version 10.4 with eight security fixes affecting components including sftp, scp, sshd, ssh, and ssh-agent, addressing issues such as malicious-server file write and traversal problems, a pre-authentication denial of service, and a client-side use-after-free bug. The release also introduced experimental composite post-quantum signatures using ML-DSA 44 with Ed25519 and protocol hardening changes including stricter post-authentication rekey handling and fatal seccomp sandbox initialization failures on Linux.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceseclists.org
Open sourcelinuxsecurity.com
Open sourceopenwall.com
Open sourceopennet.ru
Open sourceopennet.me
Open sourcelists.mindrot.org
Open sourcecdn.openbsd.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.