PT-2026-79132 · Tor · Tor
CVE-2026-77584
·
Published
2026-08-20
·
Updated
2026-08-25
CVSS v3.1
7.0
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Tor versions prior to 0.4.9.10
Description
The software fails to reject a CONFLUX LINK cell when it arrives on a circuit that already has attached streams. A malicious client can send a RELAY COMMAND BEGIN before the CONFLUX LINK on the same circuit, attaching an exit stream. This process results in an orphan stream and a dangling circuit back-pointer, leading to a use-after-free (UAF) condition—a scenario where the program continues to use a pointer after the memory it points to has been freed—when the circuit is released.
Recommendations
Update to version 0.4.9.10 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tor