CVE-2026-77587
5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| torproject | Tor | 0.4.8.1-alpha < 0.4.9.11 | affected |
Weaknesses
- CWE-911: CWE-911 Improper Update of Reference Count
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.