oss-sec mailing list archives

Re: Fwd: Tor Project Forum: Security Release 0.4.9.12


From: Sam James <sam () cmpct info>
Date: Thu, 24 Sep 2026 06:35:57 +0100

Sam James <sam () cmpct info> writes:

Here's the relevant release notes at the link in the email below:
"""
Changes in version 0.4.9.12 - 2026-09-08
  Another security release containing several high security fixes reported by
  the exciting and controversial world of LLMs. One important note is that new
  protocol versions are recommended for clients and relays (41316).
  Furthermore, authorities will NOT accept relay descriptor containing TAP keys
  anymore hence the importance for all relays to upgrade to the latest 0.4.9.x
  stable version. We very strongly recommend upgrading as soon as possible.

These bugs are public now. They're accessible at
https://gitlab.torproject.org/tpo/core/tor/-/work_items/XXXX.


  o Major bugfixes (security):
[...]

    - Fix a bug where a hostile cache could trick a client into falsely
      believing that certain relays' microdescriptors or router
      descriptors were unusable. Fixes bug 41358; bugfix on 0.2.6.1-alpha
      or earlier. Tracked as TROVE-2026-034.

From a quick look, this appears to be the most significant one, as a
malicious guard can influence circuit building to relays of its
choosing, without the tampering being detected by tor.

[....]

sam

Attachment: signature.asc
Description:


Current thread: