I would also like to see this fixed in trixie. Especially because tools
like ssh-audit suggest to set PerSourceMaxStartups to 1 to "protect"
against dheat DoS attacks.

Is that severe enough for stable-proposed-updates and then a point
release? IMHO yes. Especially because this was working in bookworm and
is now broken in trixie.

[1]:
https://github.com/jtesta/ssh-audit/blob/4f9a630de4292663bd50fff4dfa347c53316ca37/src/ssh_audit/hardening_guides.py#L67

Reply via email to