[Git][security-tracker-team/security-tracker][master] tor fixed in sid

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 9 22:03:26 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
eac84082 by Moritz Muehlenhoff at 2026-09-09T23:03:12+02:00
tor fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -529,7 +529,7 @@ CVE-2026-80914 (In the Linux kernel, the following vulnerability has been resolv
 	- linux <unfixed>
 	NOTE: https://git.kernel.org/linus/560bef609fa5992745929e8d7d458b9d88dd2830 (7.3-rc1)
 CVE-2026-XXXX [TROVE-2026-043]
-	- tor <unfixed>
+	- tor 0.4.9.12-2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41341
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41336
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41326
@@ -537,31 +537,31 @@ CVE-2026-XXXX [TROVE-2026-043]
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/e71a9959ffb8f423289cecfe6c87e411caafc5d1 (tor-0.4.9.12)
 CVE-2026-XXXX [TROVE-2026-034]
-	- tor <unfixed>
+	- tor 0.4.9.12-2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41358
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/d8e9f7a3f723a6872ea9dbef1987b8161a95c2ff (tor-0.4.9.12)
 CVE-2026-XXXX [TROVE-2026-036]
-	- tor <unfixed>
+	- tor 0.4.9.12-2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41319
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/5589c25902c865e09887d09ecf567a78f2d730eb (tor-0.4.9.12)
 CVE-2026-XXXX [TROVE-2026-042]
-	- tor <unfixed>
+	- tor 0.4.9.12-2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41329
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/f2cd147f923e9a1d1b3b440642d0bf4bd2add17a (tor-0.4.9.12)
 CVE-2026-XXXX [TROVE-2026-033]
-	- tor <unfixed>
+	- tor 0.4.9.12-2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41348
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/fd74c4fedd909e68541c61f98a8027906bf4b619 (tor-0.4.9.12)
 CVE-2026-XXXX [TROVE-2026-035]
-	- tor <unfixed>
+	- tor 0.4.9.12-2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41320
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 CVE-2026-XXXX [TROVE-2026-040]
-	- tor <unfixed>
+	- tor 0.4.9.12-2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41325
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/045b6729daf381e2684c7ead2dea97dcbd4cdd4d (tor-0.4.9.12)
@@ -592,7 +592,7 @@ CVE-2026-87732 (An issue was discovered in the mirage-crypto package before 2.2.
 	NOTE: https://osv.dev/vulnerability/OSEC-2026-12
 	NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/25e7570aec91e092b347561c23f84b6ec39e7163 (v2.2.0)
 CVE-2026-87724 (Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_ ...)
-	- tor <unfixed>
+	- tor 0.4.9.12-2
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/10d4b8ffefa7c00aab2b631ed7e7f15e42cd012d (tor-0.4.9.12)
 	NOTE: aka TROVE-2026-042
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41345



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eac8408254f266fd0e898e30103f8c5d9f79ed23

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eac8408254f266fd0e898e30103f8c5d9f79ed23
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/e8c23358/attachment.htm>


More information about the debian-security-tracker-commits mailing list