All errata/sisyphus/ALT-PU-2026-10107-2
ALT-PU-2026-10107-2

Package update tor in branch sisyphus

Version0.4.9.11-alt1
Published2026-09-18
Max severityCRITICAL
Severity:

Closed issues (3)

CVE-2026-77584
HIGH8.2

Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an exit stream that would later end up orphan leaving a dangling circuit back-pointer and a use-after-free (UAF) when the circuit is freed. This is TROVE-2026-025.

Published: 2026-08-20Modified: 2026-09-16
CVSS 3.xHIGH 8.2
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
CVE-2026-77587
HIGH7.5

Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.

Published: 2026-08-20Modified: 2026-09-16
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2026-77638
CRITICAL9.0

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

Published: 2026-08-20Modified: 2026-09-16
CVSS 3.xCRITICAL 9.0
CVSS:3.x/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Closed bugs (1)

Сервис tor запускается с устаревшим параметром group