Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-87724

Опубликовано: 09 сент. 2026
Источник: debian
EPSS Низкий

Описание

Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
torfixed0.4.9.12-2package

Примечания

  • Fixed by: https://gitlab.com/torproject/tor/-/commit/10d4b8ffefa7c00aab2b631ed7e7f15e42cd012d (tor-0.4.9.12)

  • aka TROVE-2026-032

  • https://gitlab.torproject.org/tpo/core/tor/-/work_items/41345

  • https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads

EPSS

Процентиль: 18%
0.0026
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
9 дней назад

Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.

CVSS3: 6.5
nvd
9 дней назад

Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.

CVSS3: 6.5
github
9 дней назад

Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial of service (crash) because of corrupted congestion-control state. This is TROVE-2026-032.

EPSS

Процентиль: 18%
0.0026
Низкий