OpenSSH 9.6 released
OpenSSH
9.6 has been released. It includes some minor improvements and a fix
for the so-called Terrapin
attack.
While cryptographically novel, the security impact of this attack is fortunately very limited as it only allows deletion of consecutive messages, and deleting most messages at this stage of the protocol prevents user authentication from proceeding and results in a stuck connection.