MGASA-2026-0392

Source
https://advisories.mageia.org/MGASA-2026-0392.html
Import Source
https://advisories.mageia.org/MGASA-2026-0392.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0392
Upstream
Published
2026-09-11T22:47:08Z
Modified
2026-09-11T23:00:03Z
Summary
Updated tor packages fix security vulnerabilities
Details

Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state(CVE-2026-87724) Do not purge memory for OOM from within low-level code (TROVE-2026-043). A hostile cache could trick a client into falsely believing that certain relays' microdescriptors or router descriptors were unusable (TROVE-2026-034). Fix a use-after-free error (TROVE-2026-036). Limit the size of consensus diffs, in bytes and in lines, to prevent a class of memory-based denial-of-service attacks (TROVE-2026-042). Negotiate CGO cryptography with every hop that supports it (TROVE-2026-033). Validate DNS names for complience whenever providing or receiving them from evdns, to limit exposure to a class of application and library bugs (TROVE-2026-035).

References
Credits

Affected packages

Mageia:10 / tor

Package

Name
tor
Purl
pkg:rpm/mageia/tor?arch=source&distro=mageia-10

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.9.12-1.mga10

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0392.json"

Mageia:9 / tor

Package

Name
tor
Purl
pkg:rpm/mageia/tor?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.9.12-1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0392.json"