OpenSSH 10.5 Addresses ssh-agent Lock Bypass Vulnerability

OpenSSH 10.5 Addresses ssh-agent Lock Bypass Vulnerability

First seen 11 Aug 2026, 12:08 UTC Feeds2.FeedburnerFeeds.4Sysops 74% similarity 57.8

Article Content

Browse articles
ThreatCluster

OpenSSH 10.5 was released on August 11, 2026, to address a security flaw in the ssh-agent that allowed forwarded sessions to bypass local locking mechanisms. This vulnerability could potentially expose decrypted private keys stored in the agent, affecting users who utilize agent forwarding. The flaw was identified in OpenSSH 10.4, where locking the ssh-agent inadvertently disabled checks for requests originating from local versus forwarded connections. Additionally, the update includes a patch for a use-after-free vulnerability in the ssh client and restores the full functionality of the 'restrict' option for tunnel forwarding. Users are encouraged to update to the latest version to mitigate these risks.

Key Points: • OpenSSH 10.5 fixes a critical ssh-agent lock bypass vulnerability. • The flaw allowed forwarded sessions to perform operations intended for local use. • Users are advised to upgrade to OpenSSH 10.5 to secure their private keys.

ThreatCluster AI How this analysis works

Timeline

2026-08-11
OpenSSH 10.5 released
The new version addresses a flaw in ssh-agent that allowed forwarded sessions to bypass local locks, enhancing security for users.
Feeds.4Sysops
2026-08-11
Vulnerability discovered in OpenSSH 10.4
The flaw in OpenSSH 10.4 was identified, which compromised the security of the ssh-agent when locked.
Feeds2.Feedburner

Community

Browse all →

Tracked Entities in This Story