openSUSE-SU-2026:0306-1: important: Security update for tor

[email protected]
Newsgroups gmane.linux.suse.security.announce
Message-ID <[email protected]>
   openSUSE Security Update: Security update for tor
______________________________________________________________________________

Announcement ID:    openSUSE-SU-2026:0306-1
Rating:             important
References:         #1275918 #1275919 #1275920 
Cross-References:   CVE-2026-77584 CVE-2026-77587 CVE-2026-77638
                   
Affected Products:
                    openSUSE Backports SLE-15-SP7
______________________________________________________________________________

   An update that fixes three vulnerabilities is now available.

Description:

   This update for tor fixes the following issues:

   - Update to 0.4.9.11
     * Major bugfixes
       + onion services: Prevent a race condition (boo#1275918,
         CVE-2026-77638)
       + client: no longer assert and exit if an onion service encodes an
         all-zero public key for one of its introduction points
       + directory authorities: Stop allowing 0 as a port in exit policy lines
       + security, conflux: Fix a use-after-free (and potential double free)
         (boo#1275919, CVE-2026-77587, TROVE-2026-026)
   - Update to 0.4.9.10
     * Major bugfixes
       + conflux, security: Reject a CONFLUX_LINK cell that arrives on a
         circuit which already has attached streams. (boo#1275920,
         CVE-2026-77584, TROVE-2026-025)
       + client: Resume warning about unsafe socks protocols when SafeSocks
         is not set. Also resume warning every time when TestSocks is set.
       + Make clients more consistently expire entry guards 48 to 60 days
         after they are first used.


Patch Instructions:

   To install this openSUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - openSUSE Backports SLE-15-SP7:

      zypper in -t patch openSUSE-2026-306=1



Package List:

   - openSUSE Backports SLE-15-SP7 (aarch64 ppc64le s390x x86_64):

      tor-0.4.9.11-bp157.2.15.1


References:

   https://www.suse.com/security/cve/CVE-2026-77584.html
   https://www.suse.com/security/cve/CVE-2026-77587.html
   https://www.suse.com/security/cve/CVE-2026-77638.html
   https://bugzilla.suse.com/1275918
   https://bugzilla.suse.com/1275919
   https://bugzilla.suse.com/1275920
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.