Am I correct that YubiKey users are unaffected by this vulnerability? As I understand it, the private key never enters into memory.
I use a smartcard with a NIST SP 800-73 applet on it for all my SSH (and TLS) sessions and do not have any other SSH keys.