{"id":"openSUSE-SU-2026:20709-1","summary":"Security update for tor","details":"This update for tor fixes the following issues:\n\nChanges in tor:\n\n- Update to 0.4.9.8\n  * Fix out-of-bounds read (boo#1264341, CVE-2026-44597, TROVE-2026-011)\n  * Do not attempt or accept BEGIN_DIR via conflux legs\n    (boo#1264342, CVE-2026-44599,TROVE-2026-008)\n  * Adjust conflux out-of-order queue accounting when clearing a queue\n    (boo#1264343, CVE-2026-44600, TROVE-2026-010)\n  * Fix a client-side crash caused by double-close of a circuit while\n    under circuit queue memory pressure\n    (boo#1264344, CVE-2026-44601, TROVE-2026-009)\n  * Fix null pointer dereference when receiving a CERT cell out of\n    order (boo#1264345, CVE-2026-44602, TROVE-2026-006)\n  * Fix off-by-one out-of-bounds read if a malformed BEGIN cell is\n    received (boo#1264346, CVE-2026-44603, TROVE-2026-007)\n\n- upate to 0.4.9.5:\n  * first stable release in the 0.4.9 series\n  * introduces a new circuit-level encryption design for better\n    client security\n  * introduce a more scalable way for large relay operators to\n    annotate which relays they run so clients can avoid using too\n    many of them in a single circuit\n","modified":"2026-05-11T08:15:34.311551Z","published":"2026-05-09T08:44:51Z","related":["CVE-2026-44597","CVE-2026-44599","CVE-2026-44600","CVE-2026-44601","CVE-2026-44602","CVE-2026-44603"],"upstream":["CVE-2026-44597","CVE-2026-44599","CVE-2026-44600","CVE-2026-44601","CVE-2026-44602","CVE-2026-44603"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264341"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264342"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264343"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264344"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264345"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264346"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44597"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44599"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44600"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44601"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44602"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-44603"}],"schema_version":"1.7.5"}