{"id":"openSUSE-SU-2026:20589-1","summary":"Security update for tor","details":"This update for tor fixes the following issues:\n\nChanges in tor:\n\n- update to 0.4.8.23:\n  * Fix a memory compare using the wrong length. This could lead to\n    a remote crash when using the conflux subsystem\n    (TROVE-2026-004, boo#1262302)\n  * Fix a series of defense in depth security issues found across\n    the codebase\n  * Regenerate fallback directories generated on March 25, 2026.\n  * Update the geoip files to match the IPFire Location Database,\n    as retrieved on 2026/03/25.\n- includes changes from 0.4.8.22:\n  * Avoid an out-of-bounds read error that could occur with\n    V1-formatted EXTEND cells\n    (TROVE-2025-016, boo#1262301)\n  * Allow old clients to fetch the consensus even if they use\n    version 0 of the SENDME protocol\n  * Do not check for compression bombs for buffers smaller than\n    5MB (increased from 64 KB)\n  * Improvements to directory server statistics\n\n- update to 0.4.8.21:\n  * This release is a continuation of the previous one and\n    addresses additional Conflux-related issues identified through\n    further testing and feedback from relay operators. We strongly\n    recommend upgrading as soon as possible.\n  * Major bugfixes (conflux, exit):\n    - When dequeuing out-of-order conflux cells, the circuit\n    could be close in between two dequeue which could lead to a\n    mishandling of a NULL pointer. Fixes bug 41162;\n  * Add -mbranch-protection=standard for arm64.\n  * Regenerate fallback directories generated on November\n  * Update the geoip files to match the IPFire Location\n    Database, as retrieved on 2025/11/17.\n  * Fix a bug causing the initial tor process to hang\n    intead of exiting with RunAsDaemon, when pluggable transports\n    are used.\n\n- 0.4.8.20\n  * Add a new hardening compiler flag -fcf-protection=full\n  * Fix the root cause of some conflux fragile asserts\n  * Fix a series of conflux edge cases\n\n- 0.4.8.19\n  * Fix some clients not being able to connect to LibreSSL relays\n  * Improve stream flow control performance\n","modified":"2026-04-22T08:17:24.154270Z","published":"2026-04-20T18:28:52Z","references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262301"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262302"}],"affected":[{"package":{"name":"tor","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/tor&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.8.23-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"tor":"0.4.8.23-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20589-1.json"}}],"schema_version":"1.7.5"}