Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-77587

Опубликовано: 20 авг. 2026
Источник: debian

Описание

Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
torfixed0.4.9.11-1package
torend-of-lifebullseyepackage

Примечания

  • https://gitlab.torproject.org/tpo/core/tor/-/work_items/41306

Связанные уязвимости

CVSS3: 5.9
ubuntu
7 дней назад

security update

CVSS3: 5.9
nvd
7 дней назад

Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.

CVSS3: 5.9
github
7 дней назад

Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.