# https://www.openssh.org/releasenotes.html#10.6 Future deprecation notice ------------------------- 将来非推奨となる機能の告知 * scp(1): begin deprecating the -R flag, which is used to perform a remote-to-remote copy by executing scp on a remote host. This option is a fragile optimisation that is difficult to use because it requires credentials on the remote host. It also creates security risks if the shell quoting rules on the remote system where the copy is performed differ from the client's expectations. scp(1): リモートホスト上で scp を実行することでリモートからリモートへの コピーを行うために使われる -R フラグの非推奨化を開始する。このオプションは リモートホスト上に認証情報を必要とするため使いにくい、壊れやすい最適化 である。また、コピーが実行されるリモートシステムのシェルのクオート規則が クライアントの想定と異なる場合、セキュリティ上のリスクを生じる。 From OpenSSH 10.6, this option will continue to work but will cause a deprecation warning to be emitted to standard error. In a future release, the option will be ignored and will leave in place the default remote-to-remote copy behaviour (copy via the host running scp). OpenSSH 10.6 からは、このオプションは引き続き動作するが、標準エラー出力に 非推奨の警告が出力される。将来のリリースでは、このオプションは無視され、 デフォルトのリモートからリモートへのコピーの挙動 (scp を実行している ホストを経由したコピー) のままとなる。 * sshd(8): support for platforms that do not allow file descriptor passing and that also require root privilege for PTY allocation will be removed in a future release. Affected platforms are known to include SCO OpenServer 5 and QNX 6 but may include other similarly old operating systems. This deprecation can be avoided if the user community for these platforms is able to assist us in building alternatives, such as avoiding the need for root in PTY allocation. sshd(8): ファイル記述子の受け渡しができず、かつ PTY の割り当てに root 権限を必要とするプラットフォームのサポートは、将来のリリースで削除される。 影響を受けるプラットフォームには SCO OpenServer 5 と QNX 6 が含まれることが わかっているが、同様に古い他のオペレーティングシステムも含まれる可能性が ある。これらのプラットフォームのユーザーコミュニティが、PTY の割り当てに root を必要としないようにするなどの代替手段の構築を支援してくれるなら、 この非推奨化は回避できる。 Potentially-incompatible changes -------------------------------- 互換性がなくなる可能性がある変更 * ssh(1), sshd(8): compression will be less effective as a result of the change noted below in the "Security" section ssh(1), sshd(8): 以下の「セキュリティ」の節に記載した変更の結果、 圧縮の効果が低くなる。 * ssh(1): destination usernames entered on the commandline are now more stricly checked and will refuse usernames that include backslash and dollar symbols. Usernames that are specified by the "User" directive in configuration files are no subject to these restrictions. This motivation for this change is mentioned below in the "Security" section. ssh(1): コマンドラインで入力された接続先のユーザー名がより厳密に チェックされるようになり、バックスラッシュとドル記号を含むユーザー名は 拒否される。設定ファイルの "User" ディレクティブで指定されたユーザー名は この制限の対象とならない。この変更の動機は、以下の「セキュリティ」の節で 述べる。 * sshd(8): on platforms that do not support file descriptor passing and that require root for PTY allocation, the GatewayPorts and StreamLocalForwarding options are forcibly disabled. The motivation for this changes is discussed below in the "Security" section. sshd(8): ファイル記述子の受け渡しをサポートせず、かつ PTY の割り当てに root を必要とするプラットフォームでは、GatewayPorts と StreamLocalForwarding オプションが強制的に無効にされる。この変更の動機は、 以下の「セキュリティ」の節で議論する。 Changes since OpenSSH 10.5 ========================== OpenSSH 10.5 からの変更点 This release contains a number of security fixes, several new features and some small bugfixes. このリリースには、多数のセキュリティ修正、いくつかの新機能、いくつかの 小さなバグ修正が含まれている。 Security ======== セキュリティ * sftp(1): more strictly validate paths returned from the server to avoid some cases where a server could return paths that could manipulate a recursive copy operation into writing outside its target directory. Report and patch from Junghoon Cho. sftp(1): サーバから返されたパスをより厳密に検証し、サーバが再帰コピー 操作を操作して対象ディレクトリの外へ書き込ませるようなパスを返しうる いくつかのケースを回避する。Junghoon Cho による報告とパッチ。 * sshd(8): when GSSAPIAuthentication is in use, only store GSSAPI credentials when authentication has succeeded. Avoids a situation where credentials from a failed GSSAPIAuthentication attempt may persist and be made inappropriately available if another authentication subsequently succeeds. Issue report and patch from Moritz Theile. sshd(8): GSSAPIAuthentication が使われている場合、認証が成功したときに のみ GSSAPI の認証情報を保存する。失敗した GSSAPIAuthentication の試行の 認証情報が残り、その後に別の認証が成功した場合に不適切に利用可能に なってしまう状況を回避する。Moritz Theile による問題の報告とパッチ。 * sshd(8): reset GSSAPIAuthentication before authentication, avoiding state from one authentication attempt being confused with that of a later attempt. Report and feedback from Moritz Theile. sshd(8): 認証の前に GSSAPIAuthentication をリセットし、ある認証の試行の 状態が後の試行の状態と混同されるのを回避する。Moritz Theile による報告と フィードバック。 * sshd(8), ssh(1): disable LZ77 dictionary coder to mitigate the side-channel leaks described in "Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels" by Fabian Bäumer and Marcus Brinkmann, preprint https://arxiv.org/abs/2609.07709 (2026) sshd(8), ssh(1): Fabian Bäumer と Marcus Brinkmann による "Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels" (プレプリント https://arxiv.org/abs/2609.07709 (2026)) で述べられているサイドチャネル による漏洩を緩和するため、LZ77 辞書符号化器を無効にする。 A chosen-plaintext attack method exists which makes use of dictionary-based compression to recover secrets from one channel by interacting with the SSH session's shared compression dictionary through another channel. 辞書ベースの圧縮を利用し、別のチャンネルを通じて SSH セッションの共有 圧縮辞書とやりとりすることで、あるチャンネルから秘密を復元する選択平文 攻撃の手法が存在する。 Attacker-controlled input can recognizably reflect into the total length of transmitted ciphertexts by virtue of LZ77 replacing repeated strings with back-references into the SSH session's encoder search buffer, which is shared across all channels. For this reason, the documentation already recommended against enabling compression for connections that share trusted and untrusted traffic. LZ77 は、繰り返される文字列を、すべてのチャンネルで共有されている SSH セッションの符号化器の探索バッファへの後方参照で置き換える。そのため、 攻撃者が制御する入力は、送信される暗号文の総長に識別可能な形で反映され うる。この理由から、ドキュメントではすでに、信頼できる通信と信頼できない 通信を共有する接続では圧縮を有効にしないことを推奨していた。 This change will reduce the effectiveness of the Compression option. Users are encouraged to use application-level compression over the SSH protocol where possible, as this will typically be more effective and will be completely immune to this type of attack. この変更により Compression オプションの効果は低下する。ユーザーは、可能な 場合には SSH プロトコル上でアプリケーションレベルの圧縮を使うことが 推奨される。通常はそのほうが効果的であり、この種の攻撃の影響を完全に 受けないからである。 * ssh(1): disallow '$' and '\' characters in usernames entered on the command-line to avoid usernames from untrusted sources yielding injection in shell context via ProxyCommand, Match exec, etc. Usernames specified via the configuration files are not subject this this control. Reported by SecBuddyF KeenLab Tencent (CodeBuddy Security) ssh(1): コマンドラインで入力されたユーザー名に '$' と '\' の文字を 許可しないようにし、信頼できないソースからのユーザー名が ProxyCommand や Match exec などを経由してシェルのコンテキストでインジェクションを 引き起こすのを回避する。設定ファイルで指定されたユーザー名はこの制御の 対象とならない。SecBuddyF KeenLab Tencent (CodeBuddy Security) により 報告。 We continue to recommend against directly exposing ssh(1) and other tools' command-lines to untrusted input. Mitigations such as this can not be absolute given the variety of shells and user configurations in use. 我々は引き続き、ssh(1) や他のツールのコマンドラインを信頼できない入力に 直接さらさないことを推奨する。使われているシェルやユーザーの設定は多様で あるため、このような緩和策は完全なものにはなりえない。 * ssh-keygen(1): correct handling of Daylight Saving Time when converting dates. Previous handling could cause errors of up to +/- 1 hour (unless you are in the Antarctica/Troll timezone, where the error could be +/- 2 hours). These errors could result in creation of certificates with incorrect expiry times. bz4004; from Khush Patel ssh-keygen(1): 日付を変換する際の夏時間の扱いを修正する。以前の扱いでは 最大 +/- 1 時間の誤差が生じる可能性があった (Antarctica/Troll タイム ゾーンにいる場合は、誤差が +/- 2 時間になる可能性があった)。これらの誤差に より、有効期限が不正確な証明書が作成される可能性があった。 bz4004 Khush Patel による。 * sshd(8), ssh(1): ensure that compressed payloads don't inflate past the maximum supported packet length. Reported by Oleh Konko. sshd(8), ssh(1): 圧縮されたペイロードが、サポートされる最大のパケット長を 超えて展開されないことを保証する。Oleh Konko により報告。 * sshd(8): fully honor the authorized_keys "restrict" keyword, which was not being properly applied to tunnel forwarding (PermitTunnel, disabled by default). This is a separate problem to the one fixed in openssh-10.5. sshd(8): authorized_keys の "restrict" キーワードを完全に尊重する。 このキーワードはトンネル転送 (PermitTunnel, デフォルトで無効) に正しく 適用されていなかった。これは openssh-10.5 で修正されたものとは別の問題で ある。 * sshd(8): correctly handle some options that accept "none". Some options, including AuthorizedPrincipalsFile, were documented as accepting "none" as a way to disable them; however, when overridden by an sshd_config(5) Match keyword, this argument was being incorrectly interpreted as a literal file. With Chris Rohlf in collaboration with Claude and Anthropic Research sshd(8): "none" を受け付けるいくつかのオプションを正しく扱う。 AuthorizedPrincipalsFile を含むいくつかのオプションは、無効にする方法と して "none" を受け付けるとドキュメントに記載されていた。しかし、 sshd_config(5) の Match キーワードで上書きされた場合、この引数は誤って 文字通りのファイル名として解釈されていた。 Claude および Anthropic Research と協力した Chris Rohlf による。 * sshd(8): On OS X SDK >= 27, sandboxing is no longer supported as the API we depended upon has been removed and no obvious alternative provided. sshd(8): OS X SDK >= 27 では、依存していた API が削除され、明確な代替が 提供されていないため、サンドボックスはもはやサポートされない。 * sshd(8): on platforms that do not support file descriptor passing and that require root for PTY allocation, the post-authentication sshd-session process retains root privilege, whereas on other platforms this process runs with the privilege of the logged-in user. When sshd-session was run with elevated privlege, it could perform certain actions as root and circumvent controls that would normally have applied to the user, such as making unix domain socket connections or binding (via -R forwarding) to low- numbered TCP ports. sshd(8): ファイル記述子の受け渡しをサポートせず、かつ PTY の割り当てに root を必要とするプラットフォームでは、認証後の sshd-session プロセスは root 権限を保持する。一方、他のプラットフォームではこのプロセスは ログインしたユーザーの権限で動作する。sshd-session が昇格した権限で 実行されている場合、特定の操作を root として実行でき、unix ドメイン ソケットへの接続や (-R 転送経由での) 小さい番号の TCP ポートへのバインド など、通常はユーザーに適用されるはずの制御を回避できた。 For this reason, this release disables the GatewayPorts and StreamLocalForwarding options and support for these (few) platforms will be removed in future if no alteratives to requiring privilege in the post-authentication process are found. Affected platforms include QNX 6, SCO OpenServer 5 and builds that were made with the --disable-fd-passing configure option. この理由から、このリリースでは GatewayPorts と StreamLocalForwarding オプションを無効にする。また、認証後のプロセスで権限を必要とすることへの 代替手段が見つからない場合、これらの (少数の) プラットフォームの サポートは将来削除される。影響を受けるプラットフォームには、QNX 6, SCO OpenServer 5, --disable-fd-passing configure オプション付きで作成 されたビルドが含まれる。 This problem was reported separately by sn0x-sharma and by Dark River. この問題は sn0x-sharma と Dark River によりそれぞれ別々に報告された。 New features ------------ 新機能 * All: enable hybrid post-quantum ssh-mldsa44-ed25519 signature algorithm. Note that this no longer uses the "@openssh.com" vendor extension suffix that the previous experimental implementation used. Keys generated with the previous experimental support must be regenerated and/or removed. 全体: ハイブリッド耐量子署名アルゴリズム ssh-mldsa44-ed25519 を有効に する。以前の実験的な実装が使っていた "@openssh.com" ベンダー拡張 サフィックスはもはや使わないことに注意。以前の実験的なサポートで生成 されたキーは、再生成および/または削除しなければならない。 * sshd(8): Add the WarnWeakCrypto option to sshd_config(5). This option was previously available for the client only. This option is enabled by default and will log when the client uses a key agreement scheme that is not post-quantum safe. sshd(8): sshd_config(5) に WarnWeakCrypto オプションを追加する。この オプションは以前はクライアントでのみ利用可能だった。このオプションは デフォルトで有効で、クライアントが耐量子安全でない鍵合意方式を使った 場合にログを記録する。 * ssh-keygen(1), ssh-add(1): preserve user-verification (PIN or biometric) requirement for resident keys loaded from a FIDO token, by checking the credential's credProtect policy. GHPR701 from Savely Krasovsky ssh-keygen(1), ssh-add(1): 認証情報の credProtect ポリシーをチェック することで、FIDO トークンから読み込まれた resident キーに対するユーザー 検証 (PIN または生体認証) の要求を保持する。 GHPR701 Savely Krasovsky による。 * ssh(1): include local and remote version strings in the ~I connection information display. ssh(1): ~I による接続情報の表示に、ローカルとリモートのバージョン文字列を 含める。 * ssh-add(1): add a -P flag to skip PIN entry for FIDO and PKCS#11 tokens that do not require it. ssh-add(1): PIN を必要としない FIDO および PKCS#11 トークンに対して PIN の 入力をスキップする -P フラグを追加する。 * sftp(1): add '-p' flag for mkdir/lmkdir to create directories as required. This flag has similar ergonomics to mkdir(1), and previously-existing directories do not cause an error. sftp(1): 必要に応じてディレクトリを作成する '-p' フラグを mkdir/lmkdir に 追加する。このフラグは mkdir(1) と同様の使い勝手で、すでに存在する ディレクトリはエラーにならない。 * ssh-keygen(1): add a "hexdump" key export mode that dumps the SSH wire-formatted key blob in hex format. Useful when writing documentation, tests, etc. E.g. `ssh-keygen -em hexdump -f /key` ssh-keygen(1): SSH のワイヤフォーマットのキー blob を 16 進形式で ダンプする "hexdump" キーエクスポートモードを追加する。ドキュメントや テストなどを書く際に便利である。例: `ssh-keygen -em hexdump -f /key` * ssh(1), sshd(8): ChannelTimeout now accepts timeouts with fractional seconds. ssh(1), sshd(8): ChannelTimeout が小数の秒数のタイムアウトを受け付ける ようになった。 * sshd(8): allow specification of the location of $SSH_AUTH_SOCK used for agent forwarding using a new AgentSocketPath option. This supports both using a user-specific path, such as the default of a subdirectory of $HOME ("user:.ssh/agent"), and the previous approach of allowing agent forwarding sockets to be located in a shared directory (e.g. "shared:/tmp"). Sockets created in shared directories will be created inside a subdirectory with a randomised name. bz3860 sshd(8): 新しい AgentSocketPath オプションを使って、エージェント転送に 使われる $SSH_AUTH_SOCK の場所を指定できるようにする。これは、デフォルト である $HOME のサブディレクトリ ("user:.ssh/agent") のようなユーザー固有の パスを使うことと、エージェント転送のソケットを共有ディレクトリ (例: "shared:/tmp") に置くことを許す以前の方法の両方をサポートする。 共有ディレクトリに作成されるソケットは、ランダムな名前のサブディレクトリ 内に作成される。 bz3860 * ssh-agent(1): allow specification of agent socket directories using a -A flag. It accepts "user:" and "shared:" directory styles similar to the sshd AgentSocketPath option. ssh-agent(1): -A フラグを使ってエージェントのソケットのディレクトリを 指定できるようにする。sshd の AgentSocketPath オプションと同様に、 "user:" と "shared:" の形式のディレクトリを受け付ける。 * sshd(8): account for public key authentication "key ok" tests separately to auth attempts. Add a `PubkeyOptions max-pk-ok:nnnn` option to allow a number of PK_OK tests (asking whether the server might accept a given public key) that do not count against MaxAuthTries, defaulting to 6 attempts. After these attempts are exhausted, further attempts count as failed authentications against MaxAuthTries. Practically, this allows more keys on disk or held in ssh-agent to be checked for use before the server disconnects. sshd(8): 公開鍵認証の "key ok" テストを認証の試行とは別に数える。 `PubkeyOptions max-pk-ok:nnnn` オプションを追加し、MaxAuthTries に 数えられない PK_OK テスト (サーバが与えられた公開鍵を受け入れるかどうかの 問い合わせ) の回数を指定できるようにする。デフォルトは 6 回である。 これらの試行を使い切った後は、それ以降の試行は MaxAuthTries に対する 認証の失敗として数えられる。実際には、これにより、サーバが切断する前に、 ディスク上や ssh-agent に保持されているより多くのキーを使用できるか チェックできるようになる。 * ssh(1), sshd(8): extend the existing TCPKeepAlive option to also support setting keepalives on sockets created for forwarding connections. Previously this option controlled keepalives on the connection socket only. TCPKeepAlive "yes" or "transport" enables keepalives on the connection socket. "TCPKeepAlive all" additionally enables them for forwarding sockets. bz3921 ssh(1), sshd(8): 既存の TCPKeepAlive オプションを拡張し、転送接続の ために作成されたソケットにもキープアライブを設定できるようにする。以前は このオプションは接続のソケットのキープアライブのみを制御していた。 TCPKeepAlive "yes" または "transport" は接続のソケットのキープアライブを 有効にする。"TCPKeepAlive all" はさらに転送のソケットのキープアライブも 有効にする。 bz3921 Bugfixes -------- バグ修正 * sshd(8), ssh(1): fix configuration matching on more Turkic languages which have disjoint dotted and dotless i/I characters, specifically Azerbaijani and Crimean Tatar. bz3991 sshd(8), ssh(1): 点付きと点なしの i/I の文字が別々に存在するさらなる テュルク系言語、具体的にはアゼルバイジャン語とクリミア・タタール語での 設定のマッチングを修正する。 bz3991 * ssh(1), sshd(8): don't attempt to set TCP_NODELAY on non-IP/IPv6 sockets. Eliminates some noise in debug logs. ssh(1), sshd(8): IP/IPv6 でないソケットに TCP_NODELAY を設定しようと しない。デバッグログのノイズを一部取り除く。 * ssh(1): fix case for ssh -G option output; bz4005 ssh(1): ssh -G オプションの出力の大文字小文字を修正する。 bz4005 * ssh(1), sshd(8): Fix ChannelTimeout specificity; previously a more specific channel type (e.g. "session:shell") could clobber a user-specified ChannelTimeout if it was less specific (e.g. "session"). Also, in some cases, the debug messages were printing 0 instead of the effective timeout. bz3994 ssh(1), sshd(8): ChannelTimeout の特定度を修正する。以前は、より特定的な チャンネルタイプ (例: "session:shell") が、ユーザーが指定したより特定的で ない ChannelTimeout (例: "session") を上書きしてしまう可能性があった。 また、いくつかのケースでは、デバッグメッセージが実際のタイムアウトでは なく 0 を表示していた。 bz3994 * sftp(1): avoid NULL dereference crash in some circumstances when a server fails a stat/lstat operation. GHPR707 sftp(1): サーバが stat/lstat 操作に失敗した際に、いくつかの状況で NULL 参照によりクラッシュするのを回避する。 GHPR707 * sshd(8): close a race condition where a SIGTERM/SIGQUIT would be ignored if it was received by the server while it was processing a SIGHUP restart request. bz3981 sshd(8): サーバが SIGHUP による再起動要求を処理している間に SIGTERM/ SIGQUIT を受け取ると、それが無視されてしまう競合状態を解消する。 bz3981 * sshd(8), ssh(1): check key and CA signature types during key parsing against allowlists (PubkeyAcceptedAlgorithms, etc) as early as possible. This reduces the attack surface presented by disabled algorithms. Suggested by and with extensive feedback from Chris Rohlf in collaboration with Claude and Anthropic Research. sshd(8), ssh(1): キーの解析中に、キーと CA の署名タイプを許可リスト (PubkeyAcceptedAlgorithms など) とできるだけ早くチェックする。これにより、 無効にされたアルゴリズムによる攻撃面が減る。Claude および Anthropic Research と協力した Chris Rohlf による提案と多くのフィードバック。 * All: switch the fallback implementation of the ed25519 signature algorithm used when libcrypto is disabled from SUPERCOP ed25519 to libsodium. The libsodium implementation includes a number of strictness checks over the original reference implementation we have used to this point and a more ergonomic API. 全体: libcrypto が無効な場合に使われる ed25519 署名アルゴリズムの フォールバック実装を、SUPERCOP ed25519 から libsodium に切り替える。 libsodium の実装には、これまで使ってきた元のリファレンス実装に比べて 多くの厳密性のチェックと、より使いやすい API が含まれている。 * ssh-add(1), ssh(1), ssh-keygen(1): fix spin on password entry when the program attempting to read a password was started in a background process group, with no TTY and with certain signals ignored. bz3995 ssh-add(1), ssh(1), ssh-keygen(1): パスワードを読もうとするプログラムが、 バックグラウンドのプロセスグループで、TTY なしで、特定のシグナルを無視 する状態で起動された場合に、パスワード入力時に空回りするのを修正する。 bz3995 * scp(1): disallow nul byte in received scp -O filename. This was not reachable in normal operation. Reported by Chua Wei Xun. scp(1): scp -O で受信したファイル名に nul バイトを許可しない。これは 通常の操作では到達不可能だった。Chua Wei Xun により報告。 * ssh-keygen(1), ssh(1), sshd(8): implement a maximum number of KDF rounds that will be accepted when writing an OpenSSH-format private key or when loading one. This limit is set quite high (1M), but ensures that a service that is passed a bad key with a ridiculously high number of rounds will eventually complete parsing it. ssh-keygen(1), ssh(1), sshd(8): OpenSSH 形式の秘密鍵を書き出す際や 読み込む際に受け付ける KDF のラウンド数の最大値を実装する。この制限は かなり高く (1M) 設定されているが、途方もなく高いラウンド数を持つ不正な キーを渡されたサービスが、最終的にはその解析を完了することを保証する。 * ssh-keygen(1): bump the default number of KDF rounds from 24 to 32 (this is a linear increase, not like bcrypt(3) which is exponential). ssh-keygen(1): KDF のデフォルトのラウンド数を 24 から 32 に増やす (これは線形の増加であり、指数的である bcrypt(3) とは異なる)。 * ssh(1): make StreamLocalBindMask properly respect Host/Match blocks and make it first-match-wins as documented. bz4013 ssh(1): StreamLocalBindMask が Host/Match ブロックを正しく尊重するように し、ドキュメントの記載どおり最初にマッチしたものが優先されるようにする。 bz4013 * sshd(8): make StreamLocalBindMask properly first-match-wins. sshd(8): StreamLocalBindMask で、正しく最初にマッチしたものが優先される ようにする。 Portability ----------- 移植性 * All: remove the NetBSD BROKEN_READ_COMPARISON workaround. This appears to be no longer required and caused pre-auth CPU spinning. 全体: NetBSD の BROKEN_READ_COMPARISON の回避策を削除する。これは もはや必要ないようであり、認証前に CPU の空回りを引き起こしていた。 * sshd(8): don't link sshd against libselinux when SELinux support is enabled (note: this library is still linked for the sshd-auth and sshd-session helper binaries). sshd(8): SELinux のサポートが有効な場合に、sshd を libselinux と リンクしない (注意: このライブラリは sshd-auth と sshd-session の ヘルパーバイナリには引き続きリンクされる)。 * sshd(8): allow madvise(..., MADV_DONTNEED_LOCKED) in the seccomp sandbox; needed by GrapheneOS' hardened allocator. bz4001 sshd(8): seccomp サンドボックスで madvise(..., MADV_DONTNEED_LOCKED) を 許可する。GrapheneOS の hardened allocator で必要となる。 bz4001 * sshd(8): restrict mremap(2) flags accepted by the seccomp sandbox. Only MREMAP_MAYMOVE is now accepted as other flags may have some utility in attack chains. Reported by: Mohammad Hossein Abedini. sshd(8): seccomp サンドボックスが受け付ける mremap(2) のフラグを制限 する。他のフラグは攻撃チェーンで何らかの役に立つ可能性があるため、 MREMAP_MAYMOVE のみを受け付けるようになった。Mohammad Hossein Abedini により報告。 * sshd(8): allow PAMServiceName in Match (regressed in 10.4). During the refactor of server option parsing, the ability to set PAMServiceName in Match blocks was accidentally disabled. sshd(8): Match 内での PAMServiceName を許可する (10.4 での退行)。 サーバのオプション解析のリファクタリング中に、Match ブロック内で PAMServiceName を設定する機能が誤って無効にされていた。 * sshd(8): the --disable-fd-passing configure option has been removed. sshd(8): --disable-fd-passing configure オプションは削除された。