https://seclists.org/oss-sec/2026/q3/917: Fwd: Tor Project Forum: Security lease 0.4.9.13
Published Sep 24, 2026
·Updated
Affected Software
1 affected component
Tor Project Tor<0.4.9.13
Frequently Asked Questions
1
What conditions are associated with the memory-safety issues tracked as TROVE-2026-051?
They could occur with some reverse-DNS virtual address configurations. The release notes describe possible memory corruption, double-free, and null-pointer dereference bugs.
2
When does the DNS PTR caching issue apply?
TROVE-2026-050 applies when DNS caching is disabled. Under that condition, incorrectly parsed response addresses could cause DNS PTR responses to be cached anyway.
3
Which Tor deployment roles need the update?
The release states that the fixes affect relays, clients, and onion services. It strongly recommends upgrading as soon as possible.