Advisories ยป MGASA-2026-0392

Updated tor packages fix security vulnerabilities

Publication date: 11 Sep 2026
Modification date: 11 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-87724

Description

Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when
CC_REQUEST was not sent, which allows remote attackers to cause a denial
of service (crash) because of corrupted congestion-control
state(CVE-2026-87724)
Do not purge memory for OOM from within low-level code (TROVE-2026-043).
A hostile cache could trick a client into falsely believing that certain
relays' microdescriptors or router descriptors were unusable
(TROVE-2026-034).
Fix a use-after-free error (TROVE-2026-036).
Limit the size of consensus diffs, in bytes and in lines, to prevent a
class of memory-based denial-of-service attacks (TROVE-2026-042).
Negotiate CGO cryptography with every hop that supports it
(TROVE-2026-033).
Validate DNS names for complience whenever providing or receiving them
from evdns, to limit exposure to a class of application and library bugs
(TROVE-2026-035).
                

References

SRPMS

10/core

9/core