>Synopsis: OpenSSH 10.2: Illegal instruction in AES-256-GCM cipher on i686
>Category: user
>Environment:
System : OpenBSD 7.8
Details : OpenBSD 7.8 (GENERIC) #113: Sun Oct 12 15:23:27 MDT 2025
[email protected]:/usr/src/sys/arch/i386/compile/GENERIC
Architecture: OpenBSD.i386
Machine : i386
>Description:
When the OpenSSH client is used on i686 (Intel Pentium 2)
the ssh process crashes due to an Illegal instruction.
A similar problem also occurs when a client tries to
connect to an OpenSSH server running on i686 using the
[email protected] cipher.
>How-To-Repeat:
From the i686, open an outgoing SSH connection to a server
where AES-256-GCM is the preferred cipher.
$ ssh [email protected]
Illegal instruction (core dumped)
$ ssh -v [email protected]
debug1: OpenSSH_10.2, LibreSSL 4.2.0
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: Connecting to routeros.example.com [10.0.0.10] port 22.
debug1: Connection established.
debug1: loaded pubkey from /home/user/.ssh/id_rsa: [...]
debug1: identity file /home/user/.ssh/id_rsa type 0
debug1: no identity pubkey loaded from /home/user/.ssh/id_rsa
debug1: Local version string SSH-2.0-OpenSSH_10.2
debug1: Remote protocol version 2.0, remote software version ROSSSH
debug1: compat_banner: no match: ROSSSH
debug1: Authenticating to routeros.example.com:22 as 'admin'
debug1: load_hostkeys: fopen /home/user/.ssh/known_hosts2: No such file
or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or
directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or
directory
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: curve25519-sha256
debug1: kex: host key algorithm: rsa-sha2-256
debug1: kex: server->client cipher: [email protected] MAC:
<implicit> compression: none
debug1: kex: client->server cipher: [email protected] MAC:
<implicit> compression: none
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: SSH2_MSG_KEX_ECDH_REPLY received
debug1: Server host key: ssh-rsa
SHA256:RUD1vfKUFpbd/J4N1iV4f3lf00QtMajqLprxVaNkKOw
debug1: load_hostkeys: fopen /home/user/.ssh/known_hosts2: No such file
or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or
directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or
directory
debug1: Host 'routeros.example.com' is known and matches the RSA host
key.
debug1: Found key in /home/user/.ssh/known_hosts:10
debug1: rekey out after 4294967296 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: Sending SSH2_MSG_EXT_INFO
Illegal instruction (core dumped)
Or try to connect to a server running on i686, e.g.
ssh -o [email protected] i686.example.com
See in /var/log/authlog on i686:
Dec 28 18:59:38 xterm sshd-session[68287]: error: mm_reap: child
terminated by signal 4
Dec 28 18:59:38 xterm sshd[17339]: Session process 68287 unpriv child
crash for connection from 10.0.0.63 to 10.0.0.11
Dec 28 18:59:38 xterm sshd[17339]: srclimit_penalise: ipv4: new
10.0.0.63/32 active penalty of 90 seconds for penalty: caused crash
>Fix:
Workaround: disable the AES-256-GCM ([email protected]) cipher.
e.g.
$ ssh -o [email protected] [email protected]
** WARNING: connection is not using a post-quantum key exchange
algorithm.
** This session may be vulnerable to "store now, decrypt later" attacks.
** The server may need to be upgraded. See https://openssh.com/pq.html
MMM MMM KKK TTTTTTTTTTT KKK
MMMM MMMM KKK TTTTTTTTTTT KKK
MMM MMMM MMM III KKK KKK RRRRRR OOOOOO TTT III KKK
KKK
MMM MM MMM III KKKKK RRR RRR OOO OOO TTT III KKKKK
MMM MMM III KKK KKK RRRRRR OOO OOO TTT III KKK
KKK
MMM MMM III KKK KKK RRR RRR OOOOOO TTT III KKK
KKK
MikroTik RouterOS 7.20.6 (c) 1999-2025 https://www.mikrotik.com/
Press F1 for help
[admin@routros] >
dmesg:
OpenBSD 7.8 (GENERIC) #113: Sun Oct 12 15:23:27 MDT 2025
[email protected]:/usr/src/sys/arch/i386/compile/GENERIC
real mem = 133709824 (127MB)
avail mem = 113573888 (108MB)
random: good seed from bootblocks
mpath0 at root
scsibus0 at mpath0: 256 targets
mainbus0 at root
bios0 at mainbus0: date 02/14/00, BIOS32 rev. 0 @ 0xfd7d0
apm0 at bios0: Power Management spec V1.2
pcibios0 at bios0: rev 2.1 @ 0xfd7d0/0x830
pcibios0: PCI IRQ Routing Table rev 1.0 @ 0xfdf60/128 (6 entries)
pcibios0: PCI Interrupt Router at 000:07:0 ("Intel 82371FB ISA" rev 0x00)
pcibios0: PCI bus #3 is the last bus
bios0: ROM list: 0xc0000/0xf000
cpu0 at mainbus0: (uniprocessor)
cpu0: Intel Celeron ("GenuineIntel" 686-class, 256KB L2 cache) 367 MHz,
06-06-0a, patch 0000000d
cpu0:
FPU,V86,DE,PSE,TSC,MSR,PAE,MCE,CX8,SEP,MTRR,PGE,MCA,CMOV,PSE36,MMX,FXSR,PERF,MELTDOWN
mtrr: Pentium Pro MTRR support, 8 var ranges, 88 fixed ranges
pci0 at mainbus0 bus 0: configuration mode 1 (bios)
pchb0 at pci0 dev 0 function 0 "Intel 82443BX AGP" rev 0x03
intelagp0 at pchb0
agp0 at intelagp0: aperture at 0xe0000000, size 0x4000000
ppb0 at pci0 dev 1 function 0 "Intel 82443BX AGP" rev 0x03
pci1 at ppb0 bus 1
vga1 at pci1 dev 0 function 0 "ATI Mach64" rev 0xdc
wsdisplay0 at vga1 mux 1: console (80x25, vt100 emulation)
wsdisplay0: screen 1-5 added (80x25, vt100 emulation)
cbb0 at pci0 dev 4 function 0 "TI PCI1220 CardBus" rev 0x02: irq 11
cbb1 at pci0 dev 4 function 1 "TI PCI1220 CardBus" rev 0x02: irq 11
pcib0 at pci0 dev 7 function 0 "Intel 82371AB PIIX4 ISA" rev 0x02
pciide0 at pci0 dev 7 function 1 "Intel 82371AB IDE" rev 0x01: DMA, channel 0
wired to compatibility, channel 1 wired to compatibility
wd0 at pciide0 channel 0 drive 0: <InnoDisk Corp. - iCF4000 4GB>
wd0: 2-sector PIO, LBA, 3940MB, 8070048 sectors
wd0(pciide0:0:0): using PIO mode 4, Ultra-DMA mode 2
atapiscsi0 at pciide0 channel 1 drive 0
scsibus1 at atapiscsi0: 2 targets
cd0 at scsibus1 targ 0 lun 0: <TOSHIBA, CD-ROM XM-1802B, 1915> removable
cd0(pciide0:1:0): using PIO mode 4, DMA mode 2
uhci0 at pci0 dev 7 function 2 "Intel 82371AB USB" rev 0x01: irq 11
piixpm0 at pci0 dev 7 function 3 "Intel 82371AB Power" rev 0x02: SMI
iic0 at piixpm0
spdmem0 at iic0 addr 0x50: 64MB SDRAM non-parity PC66CL2
maestro0 at pci0 dev 8 function 0 "ESS Maestro II" rev 0x00: irq 5
ac97: codec id 0x41445303 (Analog Devices AD1819)
ac97: codec features Analog Devices Phat Stereo
audio0 at maestro0
cardslot0 at cbb0 slot 0 flags 0
cardbus0 at cardslot0: bus 2 device 0 cacheline 0x0, lattimer 0x20
pcmcia0 at cardslot0
cardslot1 at cbb1 slot 1 flags 0
cardbus1 at cardslot1: bus 3 device 0 cacheline 0x0, lattimer 0x20
pcmcia1 at cardslot1
isa0 at pcib0
isadma0 at isa0
com0 at isa0 port 0x3f8/8 irq 4: ns16550a, 16 byte fifo
pckbc0 at isa0 port 0x60/5 irq 1 irq 12
pckbd0 at pckbc0 (kbd slot)
wskbd0 at pckbd0: console keyboard, using wsdisplay0
pms0 at pckbc0 (aux slot)
wsmouse0 at pms0 mux 0
pms0: Synaptics clickpad, firmware 4.3, 0x8858a1 0x3b470c 0x0 0x554755 0x14090d
pcppi0 at isa0 port 0x61
spkr0 at pcppi0
lpt0 at isa0 port 0x378/4 irq 7
npx0 at isa0 port 0xf0/16: reported by CPUID; using exception 16
usb0 at uhci0: USB revision 1.0
uhub0 at usb0 configuration 1 interface 0 "Intel UHCI root hub" rev 1.00/1.00
addr 1
vscsi0 at root
scsibus2 at vscsi0: 256 targets
softraid0 at root
scsibus3 at softraid0: 256 targets
root on wd0a (bbb6acad0864bfd0.a) swap on wd0b dump on wd0b
re0 at cardbus0 dev 0 function 0 "Realtek 8169" rev 0x10: RTL8169/8110SB
(0x1000), irq 11, address 00:1b:2f:bf:82:e1
rgephy0 at re0 phy 7: RTL8169S/8110S/8211, rev. 3
usbdevs:
Controller /dev/usb0:
addr 01: 8086:0000 Intel, UHCI root hub
full speed, self powered, config 1, rev 1.00
driver: uhub0