CVE-2026-106584: Low severity OpenSSH ssh-keygen vulnerability
Published Oct 6, 2026
·Updated
In ssh-keygen in OpenSSH before 10.6, certificates could have incorrect expiration times because of Daylight Saving mishandling. There can be a slightly more severe effect on users in certain Antarctic locations.
Affected Software
1 affected component
OpenSSH ssh-keygen<10.6
Event History
Oct 6, 2026
CVE Published
via MITRE·08:47 PM
Data Sourced
via MITRE·08:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations should be reviewed?
Review systems using ssh-keygen from OpenSSH versions before 10.6, particularly where SSH certificates are created or managed.
2
Are any locations subject to greater impact?
The issue can have a slightly more severe effect for users in certain Antarctic locations.