This issue has been fixed to the best ability of the maintainers by adjusting
host key ordering to always use the default if the client has learned a hostkey
matching the best-preference algorithm. Fixes beyond this are considered to
reduce overall security by the maintainers.
https://security-tracker.debian.org/tracker/CVE-2020-14145
https://docs.ssh-mitm.at/vulnerabilities/CVE-2020-14145.html