← Downloads

OpenSSH 10.5

Package v10.5 x86_64 TAR.GZ August 11, 2026

OpenSSH 10.5 patches an ssh-agent locking bypass involving session-bind, adds the ssh -Z flag for listing offered keys, improves FIDO handling, and marks a shift to more frequent security releases.

Download TAR.GZ Project website ↗

Download Mirrors

Mirror Region Download
OpenSSH (Official) Primary Global Download
OpenBSD Mirror Global Download
Release Notes Global Download

OpenSSH is the SSH implementation almost every Linux system uses, and 10.5 carries both a meaningful security fix and an announcement about how the project will ship future releases. We covered both.

The agent locking fix

The headline fix concerns ssh-agent locking and the session-bind@openssh.com extension.

Binding requests were previously rejected while the agent was locked, which sounds safe and had the opposite effect: operations meant to stay local could be performed remotely through a forwarded agent, including adding PKCS#11 tokens and using keys carrying destination restrictions.

If you forward your agent, this is the fix that matters. Agent forwarding hands the remote end the ability to ask your local agent to sign things, and destination restrictions are what is supposed to keep that scoped.

echo "$SSH_AUTH_SOCK"                      # forwarding active?
ssh-add -h host.example.com ~/.ssh/id_ed25519   # destination-restricted

Our SSH hardening guide covers why blanket ForwardAgent yes is worth avoiding, and the SSH config builder generates per-host blocks that scope it.

ssh -Z

The genuinely useful new flag prints the public keys SSH would try for authentication, in the order it would try them.

ssh -Z user@host

If you have watched a login fail because the server hit MaxAuthTries before reaching the right key, this replaces a -vvv archaeology session with one command.

Server side and FIDO

restrict in authorized_keys now correctly applies to tunnel forwarding. ssh-keygen can set or clear touch-required and verify-required on FIDO keys while resetting the passphrase, and the client tries FIDO keys not requiring user presence before those needing a PIN or biometric, which cuts spurious prompts.

Fixes also restore ChannelTimeout, RekeyLimit, and PAMServiceName behavior inside Match blocks in sshd_config.

The release cadence change

The project says it has been receiving a large volume of security reports found by or with AI assistance. Most turn out to have no meaningful implication under a realistic threat model, but the team has seen cases where an AI-surfaced vulnerability was later found independently by other researchers.

The reasoning follows: attackers running similar tooling can find the same bugs and will not file reports. So OpenSSH plans to publish releases more frequently rather than waiting for its normal schedule.

Practically, treat OpenSSH as a package that updates on its own timetable rather than yours, and make sure your patch process can absorb an off-cycle release.

Verify Your Download

Releases are signed. Signatures and instructions are on the portable OpenSSH page.