A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be added more than once in the pending list.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-0491.json"
[ { "events": [ { "introduced": "0.3.2.0" }, { "fixed": "0.3.2.10" } ] }, { "events": [ { "introduced": "0.3.2.x" }, { "fixed": "0.3.2.10" } ] } ]