A corrective release of the Tor 0.4.7.8 toolkit, used for setting up the anonymous Tor network, has been published. The new version fixes a vulnerability (CVE-2021-38385) that could be exploited to remotely initiate a denial-of-service attack. There is also a potential impact on anonymity provided by the system. The issue leads to process termination due to an assert check failing when there is a discrepancy between the verification of digital signatures in isolation and in batch mode. Details are not being disclosed until package updates in major distributions.
Source: opennet.ru