[Git][security-tracker-team/security-tracker][master] new tor issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 9 11:06:05 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b9d53ee8 by Moritz Muehlenhoff at 2026-09-09T12:04:54+02:00
new tor issues

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,40 @@
+CVE-2026-XXXX [TROVE-2026-043]
+	- tor <unfixed>
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41341
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41336
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41326
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41363
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
+	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/e71a9959ffb8f423289cecfe6c87e411caafc5d1 (tor-0.4.9.12)
+CVE-2026-XXXX [TROVE-2026-034]
+	- tor <unfixed>
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41358
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
+	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/d8e9f7a3f723a6872ea9dbef1987b8161a95c2ff (tor-0.4.9.12)
+CVE-2026-XXXX [TROVE-2026-036]
+	- tor <unfixed>
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41319
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
+	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/5589c25902c865e09887d09ecf567a78f2d730eb (tor-0.4.9.12)
+CVE-2026-XXXX [TROVE-2026-042]
+	- tor <unfixed>
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41329
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
+	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/f2cd147f923e9a1d1b3b440642d0bf4bd2add17a (tor-0.4.9.12)
+CVE-2026-XXXX [TROVE-2026-033]
+	- tor <unfixed>
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41348
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
+	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/fd74c4fedd909e68541c61f98a8027906bf4b619 (tor-0.4.9.12)
+CVE-2026-XXXX [TROVE-2026-035]
+	- tor <unfixed>
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41320
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
+CVE-2026-XXXX [TROVE-2026-040]
+	- tor <unfixed>
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41325
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
+	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/045b6729daf381e2684c7ead2dea97dcbd4cdd4d (tor-0.4.9.12)
 CVE-2026-8615 (The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-87747 (The Enterprise Cloud Database developed by Ragic has an Arbitrary File ...)
@@ -27,6 +64,9 @@ CVE-2026-87732 (An issue was discovered in the mirage-crypto package before 2.2.
 CVE-2026-87724 (Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_ ...)
 	- tor <unfixed>
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/10d4b8ffefa7c00aab2b631ed7e7f15e42cd012d (tor-0.4.9.12)
+	NOTE: aka TROVE-2026-042
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41345
+	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 CVE-2026-87658 (Information leak in Extensions in Google Chrome prior to 153.0.8010.36 ...)
 	- chromium <unfixed>
 CVE-2026-87657 (Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -158,6 +158,8 @@ tomcat10
 --
 tomcat11
 --
+tor
+--
 unbound
   Michael Tokarev is working on rebasing to 1.25.2 (possibly 1.26.0)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b9d53ee8c8a32939dc680a7542b95ad764f16609

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b9d53ee8c8a32939dc680a7542b95ad764f16609
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/41cd5cb6/attachment.htm>


More information about the debian-security-tracker-commits mailing list