An update that solves 6 vulnerabilities and has 6 bug fixes can now be installed.. openSUSE security update: security update for tor ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20709-1 Rating: critical References: * bsc#1264341 * bsc#1264342 * bsc#1264343 * bsc#1264344 * bsc#1264345 * bsc#1264346 Cross-References: * CVE-2026-44597 * CVE-2026-44599 * CVE-2026-44600 * CVE-2026-44601 * CVE-2026-44602 * CVE-2026-44603 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 6 vulnerabilities and has 6 bug fixes can now be installed. Description: This update for tor fixes the following issues: Changes in tor: - Update to 0.4.9.8 * Fix out-of-bounds read (boo#1264341, CVE-2026-44597, TROVE-2026-011) * Do not attempt or accept BEGIN_DIR via conflux legs (boo#1264342, CVE-2026-44599,TROVE-2026-008) * Adjust conflux out-of-order queue accounting when clearing a queue (boo#1264343, CVE-2026-44600, TROVE-2026-010) * Fix a client-side crash caused by double-close of a circuit while under circuit queue memory pressure (boo#1264344, CVE-2026-44601, TROVE-2026-009) * Fix null pointer dereference when receiving a CERT cell out of order (boo#1264345, CVE-2026-44602, TROVE-2026-006) * Fix off-by-one out-of-bounds read if a malformed BEGIN cell is received (boo#1264346, CVE-2026-44603, TROVE-2026-007) - upate to 0.4.9.5: * first stable release in the 0.4.9 series * introduces a new circuit-level encryption design for better client security * introduce a more scalable way for large relay operators to annotate which relays they run so clients can avoid using too many of them in a single circuit Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for yourproduct: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-236=1 Package List: - openSUSE Leap 16.0: tor-0.4.9.8-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-44597.html * https://www.suse.com/security/cve/CVE-2026-44599.html * https://www.suse.com/security/cve/CVE-2026-44600.html * https://www.suse.com/security/cve/CVE-2026-44601.html * https://www.suse.com/security/cve/CVE-2026-44602.html * https://www.suse.com/security/cve/CVE-2026-44603.html . This security advisory addresses critical vulnerabilities in tor with installation instructions for openSUSE Leap 16.0.. openSUSE Update tor Bug Fix Critical Update. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.