Corrective releases of the Tor toolkit 0.4.8.25 and 0.4.9.8, used to operate the anonymous Tor network, have been published. Release Tor 0.4.9.8 fixes 6 vulnerabilities:
- TROVE-2026-011 — an error that led to reading data from outside the buffer when processing specially formatted messages (cell) END, TRUNCATE, and TRUNCATED;
- TROVE-2026-008 — incorrect handling of BEGIN_DIR messages when using the conflux mechanism.
- TROVE-2026-010 — in the conflux mechanism, the counters and state variables were incorrectly recalculated when clearing the queue of unordered messages.
- TROVE-2026-009 — a client crash caused by double-closing the chain when there is insufficient free memory for queue operations.
- TROVE-2026-006 — dereferencing a null pointer that may occur when processing a specially formatted CERT message.
- TROVE-2026-007 — reading from outside the allocated buffer that occurs when processing a specially formatted BEGIN message.
Debian has already released the tor package update 0.4.9.8-0+deb13u1 for the stable distribution version and 0.4.9.8-1 for unstable. The vulnerability fixes are included in the Tor Browser 15.0.13 and Tails 7.7.3 releases.
A few days ago, the release of Arti 2.3.0, an implementation of the Tor toolkit written in Rust, was also published. When the Arti code reaches a level that can fully replace the C version, Tor developers intend to elevate Arti to the primary Tor implementation status and gradually discontinue support for the C implementation. The new version has advances in functionality for relays and servers directories (Directory Authority), added a new RPC API for inspecting tunnels, provided support for logging via syslog, and added the logging.protocol_warnings setting to reflect protocol misuse warnings in the log.
Source: opennet.ru
