🔒 Security & Privacy

OpenSSH 10.3 Finally Plugs a Username Metacharacter Hole

What if your SSH login name was secretly executing code? OpenSSH 10.3 just fixed that nightmare — plus more housekeeping that old servers won't like.

OpenSSH 10.3 release notes with security patch highlights

⚡ Key Takeaways

  • Critical fix for metacharacter validation in usernames prevents auth exploits. 𝕏
  • Drops compatibility for non-rekeying SSH clients — modernize or bust. 𝕏
  • scp now safely strips setuid/setgid bits in root legacy mode. 𝕏
Published by

Open Source Beat

Community-driven. Code-first.

Worth sharing?

Get the best Open Source stories of the week in your inbox — no noise, no spam.

Originally reported by LWN.net

Stay in the loop

The week's most important stories from Open Source Beat, delivered once a week.