PT-2026-79132 · Tor · Tor

CVE-2026-77584

·

Published

2026-08-20

·

Updated

2026-08-25

CVSS v3.1

7.0

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Tor versions prior to 0.4.9.10
Description The software fails to reject a CONFLUX LINK cell when it arrives on a circuit that already has attached streams. A malicious client can send a RELAY COMMAND BEGIN before the CONFLUX LINK on the same circuit, attaching an exit stream. This process results in an orphan stream and a dangling circuit back-pointer, leading to a use-after-free (UAF) condition—a scenario where the program continues to use a pointer after the memory it points to has been freed—when the circuit is released.
Recommendations Update to version 0.4.9.10 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77584
OPENSUSE-SU-2026:11590-1
OPENSUSE-SU-2026:21660-1

Affected Products

Tor