VYPR

rpm package

opensuse/tor&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/tor&distro=openSUSE%20Leap%2016.0

Vulnerabilities (3)

  • CVE-2026-77638HigAug 20, 2026
    affected < 0.4.9.11-bp160.1.1fixed 0.4.9.11-bp160.1.1

    Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

  • CVE-2026-77587MedAug 20, 2026
    affected < 0.4.9.11-bp160.1.1fixed 0.4.9.11-bp160.1.1

    Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.

  • CVE-2026-77584HigAug 20, 2026
    affected < 0.4.9.11-bp160.1.1fixed 0.4.9.11-bp160.1.1

    Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an exit stream that would later end up orphan leaving a