Updated tor packages fix security vulnerabilities
Publication date: 08 Sep 2026Modification date: 08 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-77584 , CVE-2026-77587 , CVE-2026-77638 , CVE-2026-77639 , CVE-2026-77640 , CVE-2026-77641 , CVE-2026-77642
Description
An out-of-bounds write when parsing a consensus or detached signature
with unexpected signature digest type (CVE-2026-77642).
A NULL write after free when sending a CONFLUX_SWITCH cell fails,
resulting in a crash (CVE-2026-77641).
An infinite loop when decompressing a truncated zlib/gzip stream with
done=1 (CVE-2026-77640).
A compression bomb bypass where an attacker could concatenate many gzip
or zlib sub-streams (CVE-2026-77639).
A race condition where in just the right circumstances a rendezvous
point could man-in-the-middle (impersonate) the onion service that the
client was trying to reach (CVE-2026-77638).
A use-after-free that a malicious exit node could use to crash a client
(CVE-2026-77587).
Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a
circuit which already has attached streams (CVE-2026-77584).
References
- https://bugs.mageia.org/show_bug.cgi?id=36213
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/J3OOWWFCIOAR7SCIVWYWCHHV6G2BGSPN/
- https://lists.debian.org/debian-security-announce/2026/msg00283.html
- https://www.cve.org/CVERecord?id=CVE-2026-77584
- https://www.cve.org/CVERecord?id=CVE-2026-77587
- https://www.cve.org/CVERecord?id=CVE-2026-77638
- https://www.cve.org/CVERecord?id=CVE-2026-77639
- https://www.cve.org/CVERecord?id=CVE-2026-77640
- https://www.cve.org/CVERecord?id=CVE-2026-77641
- https://www.cve.org/CVERecord?id=CVE-2026-77642
SRPMS
10/core
- tor-0.4.9.11-1.mga10
9/core
- tor-0.4.9.11-1.mga9