Here's the relevant release notes at the link in the email below: """ Changes in version 0.4.9.12 - 2026-09-08 Another security release containing several high security fixes reported by the exciting and controversial world of LLMs. One important note is that new protocol versions are recommended for clients and relays (41316). Furthermore, authorities will NOT accept relay descriptor containing TAP keys anymore hence the importance for all relays to upgrade to the latest 0.4.9.x stable version. We very strongly recommend upgrading as soon as possible.
o Major bugfixes (security): - Do not purge memory for OOM from within low-level code. Previously, we would handle OOM conditions from within appendcelltocircuitqueue, which could appear at various places within our call stack, and lead to objects being freed at surprising points in the code, with attendent risk of use-after- free errors. Now we only check for OOM conditions there, and handle them from much higher in the stack. Fixes bugs 41341, 41336, 41326, and 41363; bugfix on 0.2.4.14-alpha. Root-cause fix for TROVE-2026-043. - Fix a bug where a hostile cache could trick a client into falsely believing that certain relays' microdescriptors or router descriptors were unusable. Fixes bug 41358; bugfix on 0.2.6.1-alpha or earlier. Tracked as TROVE-2026-034. - Fix a use-after-free error that could occur if AutomapHostsOnResolve was set. Applications using AutomapHostsOnResolve with IPv4, or with small VirtualAddrNetwork values, are especially vulnerable. Fixes bug 41319; bugfix on 0.2.1.29. Tracked as TROVE-2026-036. - Limit the size of consensus diffs, in bytes and in lines, to prevent a class of memory-based denial-of-service attacks. Fixes bug 41329; bugfix on 0.3.1.1-alpha. This is tracked as TROVE-2026-042. - Negotiate CGO cryptography with every hop that supports it. Previously, we failed to negotiate CGO with hops other than the final hop of a circuit, since we did not enable congestion-control with those hops. Now, we negotiate congestion-control and CGO whenever we can. Fixes bug 41348; bugfix on 0.4.9.3-alpha. Tracked as TROVE-2026-033. - Reject the CCRESPONSE extension in any handshakes for which congestion control was not requested. Previously, clients would interpret this extension, which could put congestion control into an invalid state, leading to a possible remote crash attack. Fixes bug 41345; bugfix on 0.4.9.3-alpha. Tracked as TROVE-2026-032. - Validate DNS names for complience whenever providing or receiving them from evdns, to limit exposure to a class of application and library bugs. Fixes bug 41320; bugfix on 0.1.1.23. Resolves TROVE-2026-035.
o Major bugfixes (conflux, client, stream isolation): - Keep the stream isolation state in sync of a linked conflux set on every leg when attaching new streams. This is TROVE-2026-040. Fixes bug 41325; bugfix on 0.4.8.1-alpha.
o Minor feature (authority): - Reject 0.4.8.x series at the authority level. Closes ticket 41234.
o Minor features (directory authority): - Authorities now recommend additional protocols for clients and relays. Part of ticket 41316. - Provide a new AuthDirSupport048Clients option, which is disabled by default. When this option is disabled, authorities will accept router descriptors that do not contain TAP keys, and will be willing to generate microdescriptors without TAP keys in response to such descriptors. This introduces a new consensus method (36). Part of ticket 41316.
o Minor features (fallbackdir): - Regenerate fallback directories generated on September 08, 2026.
o Minor features (geoip data): - Update the geoip files to match the IPFire Location Database, as retrieved on 2026/09/08.
o Minor features (portability): - Fix seccomp compilation with recent versions of glibc. (Closes ticket 41317.)
o Minor bugfixes (controller): - Fix an assert that can happen if a controller requests an HSFETCH naming a relay that has a local descriptor but isn't in the consensus. Fixes bug 41367; bugfix on 0.2.7.1-alpha.
o Minor bugfixes (directory authorities): - If two shared-random-value commitments are equal, directory authorities now tie-break by authority identity during the reveal phase. Equal commits could happen if an evil authority republishes another's public commitment (and later its public reveal) as its own. Previously the two tied entries could cause honest authorities to disagree about the resulting SRV. Fixes bug 41356; bugfix on 0.2.9.1-alpha.
o Removed features: - Tor clients no longer accept consensus instructions to downgrade the congestion control algorithm. This is defense-in-depth for issues like 41345. Implements ticket 41361. """
-------------------- Start of forwarded message -------------------- Date: Tue, 08 Sep 2026 20:14:49 +0000 From: David Goulet <noreply () forum torproject org> To: sam () cmpct info Subject: Tor Project Forum: Security Release 0.4.9.12 Where to Download
Tarballs Gitlab Repository Bug Report
Changes
Below are the major changes of the released versions and links to more detailed release notes.
Stable
Today, we released stable version 0.4.9.12 to address a series of high-severity security issues and some minor new features.
We expect to make the related tickets public roughly one week from today. Until then, the only publicly available details about these security issues can be found in the ReleaseNotes file (see below).
We strongly recommend updating as soon as possible. Debian packages are already available here, and packages for other distributions should follow shortly after this announcement.
Final note: We are actively working on additional important security issues, so starting today, we are moving C-tor releases to a two-week cadence. This means that the next release, 0.4.9.13, is expected around September 22.
Nothing is set in stone, however, as the recent flurry of security issues may require us to adapt quickly.
Release Notes
0.4.9.x
--- Visit Topic or reply to this email to respond.
[stripped HTML content] -------------------- End of forwarded message --------------------
Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.
tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches ZSTREAMEND, causing zlib to return ZBUFERROR with no input remaining, which bufaddcompress() mistook for a full output buffer and retried forever. Fixed by returning TORCOMPRESSERROR in that case so the caller can abort cleanly. This is TROVE-2026-021.
Tor before 0.4.9.10 did not reject a CONFLUXLINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAYCOMMANDBEGIN before the CONFLUXLINK on the same circuit, attaching an exit stream that would later end up orphan leaving a dangling circuit back-pointer and a use-after-free (UAF) when the circuit is freed. This is TROVE-2026-025.
Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.
Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009.
Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
Tor before 0.4.9.7 can attempt or accept BEGINDIR via conflux legs, aka TROVE-2026-008.
Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010.
Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
From diffing 0.4.9.6 and 0.4.9.7 [0]: +Changes in version 0.4.9.7 - 2026-05-06 + This is a security release fixing several major bugfixes that were reported + in the past weeks. Huge thanks to everyone that reported these issues! We + strongly recommend upgrading as soon as possible. + + o Major bugfixes (cell handling): + - Fix out-of-bounds read (OOB) when END, TRUNCATE and TRUNCATED cell + have no reason in their payload. TROVE-2026-011. Found by Found by + Brian Carpenter (geeknik). Fixes bug 41254; bugfix + on 0.1.1.1-alpha. + + o Major bugfixes (conflux): + - Do not attempt or accept BEGINDIR via conflux legs. TROVE-2026- + 008. Credit to Anas Cherni from Calif.io in collaboration with + Claude and Anthropic Research. Fixes bug 41243; bugfix + on 0.4.8.1-alpha. + + o Major bugfixes (conflux, relay): + - Adjust conflux out-of-order queue accounting when clearing a + queue. TROVE-2026-010. Found by aptupdate. Fixes bug 41251; bugfix + on 0.4.8.1-alpha. + + o Major bugfixes (pathbias): + - Fix a client-side crash caused by double-close of a circuit while + under circuit queue memory pressure. TROVE-2026-009. Found by + cypherpunks. Fixes bug 41237; bugfix on 0.3.3.6-rc. + + o Major bugfixes (relay): + - Fix null pointer dereference when receiving a CERT cell out of + order. TROVE-2026-006. Found by Fwame. Fixes bug 41240; bugfix + on 0.2.4.4-alpha. + + o Major bugfixes (relay, onion service): + - Fix off-by-one out-of-bounds read if a malformed BEGIN cell is + received. TROVE-2026-007. Found by Flanagan. Fixes bug 41245; + bugfix on 0.2.4.7-alpha. + + o Minor features (fallbackdir): + - Regenerate fallback directories generated on May 06, 2026. + + o Minor features (geoip data): + - Update the geoip files to match the IPFire Location Database, as + retrieved on 2026/05/06. +
The referenced bugs are private, so no more details are available yet. There were several recent other security releases too for Tor.
[0] https://gitlab.torproject.org/tpo/core/tor/-/blob/tor-0.4.9.7/ReleaseNotes#L5
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.
In Tor before 0.3.3.12, 0.3.4.x before 0.3.4.11, 0.3.5.x before 0.3.5.8, and 0.4.x before 0.4.0.2-alpha, remote denial of service against Tor clients and relays can occur via memory exhaustion in the KIST cell scheduler.
It was reported [1],[2] that Tor suffered from a denial of service vulnerability due to an error when handling SENDME cells. This could be exploited to cause excessive consumption of memory resources within an entry node.
This is fixed in upstream version 0.2.3.25 (git [3]).
[1] https://secunia.com/advisories/51329/ [2] https://trac.torproject.org/projects/tor/ticket/6252 [3] https://gitweb.torproject.org/arma/tor.git/commitdiff/b9b54568c0bb64c32bd0b362954bdbc8c1234b16
Tor before 0.2.3.24-rc allows remote attackers to cause a denial of service (assertion failure and daemon exit) by performing link protocol negotiation incorrectly.
Tor before 0.2.3.23-rc allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a renegotiation attempt that occurs after the initiation of the V3 link protocol.
Tor before 0.2.4.23 and 0.2.5 before 0.2.5.6-alpha maintains a circuit after an inbound RELAYEARLY cell is received by a client, which makes it easier for remote attackers to conduct traffic-confirmation attacks by using the pattern of RELAY and RELAYEARLY cells as a means of communicating information about hidden service names.
The Hidden Service (HS) client implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote servers to cause a denial of service (assertion failure and application exit) via a malformed HS descriptor.
The Hidden Service (HS) server implementation in Tor before 0.2.4.27, 0.2.5.x before 0.2.5.12, and 0.2.6.x before 0.2.6.7 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors.
bufpullup in Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle unexpected arrival times of buffers with invalid layouts, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.
Tor before 0.2.4.26 and 0.2.5.x before 0.2.5.11 does not properly handle pending-connection resolve states during periods of high DNS load, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via crafted packets.
Tor before 0.2.8.9 and 0.2.9.x before 0.2.9.4-alpha had internal functions that were entitled to expect that buft data had NUL termination, but the implementation of or/buffers.c did not ensure that NUL termination was present, which allows remote attackers to cause a denial of service (client, hidden service, relay, or authority crash) via crafted data.
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
Browser proxy settings can be bypassed by using the automount feature with autofs to create a mount point on the local file system. Content can be loaded from this mounted file system directly using a file: URI, bypassing configured proxy settings. Note: this issue only affects OS X in default configurations. On Linux systems, autofs must be installed for the vulnerability to occur and Windows is not affected.
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the connectionedgeprocessrelaycell function via a BEGINDIR cell on a rendezvous circuit.
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relaysendendcellfromedge function via a malformed BEGIN cell.
The rendserviceintroestablished function in or/rendservice.c in Tor before 0.2.8.15, 0.2.9.x before 0.2.9.12, 0.3.0.x before 0.3.0.11, 0.3.1.x before 0.3.1.7, and 0.3.2.x before 0.3.2.1-alpha, when SafeLogging is disabled, allows attackers to obtain sensitive information by leveraging access to the log files of a hidden service, because uninitialized stack data is included in an error message about construction of an introduction point circuit.
Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to defeat intended anonymity properties by leveraging the existence of large families.
An issue was discovered in Tor before 0.2.9.15, 0.3.1.x before 0.3.1.10, and 0.3.2.x before 0.3.2.10. The directory-authority protocol-list subprotocol implementation allows remote attackers to cause a denial of service (NULL pointer dereference and directory-authority crash) via a misformatted relay descriptor that is mishandled during voting.