oss-sec mailing list archives
Re: Fwd: Tor Project Forum: Security Release 0.4.9.12
From: Sam James <sam () cmpct info>
Date: Thu, 24 Sep 2026 06:35:57 +0100
Sam James <sam () cmpct info> writes:
Here's the relevant release notes at the link in the email below: """ Changes in version 0.4.9.12 - 2026-09-08 Another security release containing several high security fixes reported by the exciting and controversial world of LLMs. One important note is that new protocol versions are recommended for clients and relays (41316). Furthermore, authorities will NOT accept relay descriptor containing TAP keys anymore hence the importance for all relays to upgrade to the latest 0.4.9.x stable version. We very strongly recommend upgrading as soon as possible.
These bugs are public now. They're accessible at https://gitlab.torproject.org/tpo/core/tor/-/work_items/XXXX.
o Major bugfixes (security):
[...]
- Fix a bug where a hostile cache could trick a client into falsely
believing that certain relays' microdescriptors or router
descriptors were unusable. Fixes bug 41358; bugfix on 0.2.6.1-alpha
or earlier. Tracked as TROVE-2026-034.
From a quick look, this appears to be the most significant one, as a malicious guard can influence circuit building to relays of its choosing, without the tampering being detected by tor.
[....]
sam
Attachment:
signature.asc
Description:
Current thread:
- Fwd: Tor Project Forum: Security Release 0.4.9.12 Sam James (Sep 08)
- Re: Fwd: Tor Project Forum: Security Release 0.4.9.12 Sam James (Sep 23)
