CVE-2026-77641
Linux Debian Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-77641 is a write-after-free vulnerability in the Tor anonymity network software, tracked internally as TROVE-2026-017. It affects Tor versions from 0.4.8.1-alpha up to (but not including) 0.4.9.9, and was published on August 20, 2026. The flaw occurs in the CONFLUX_SWITCH cell handling logic, where a failed send operation can trigger a crash. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Tor ChangeLog).

Détails techniques

The root cause is an unchecked return value (CWE-252) in Tor's CONFLUX protocol implementation. When relay_send_command_from_edge() fails while sending a CONFLUX_SWITCH cell, it internally calls circuit_mark_for_close(), which removes the circuit leg via cfx_del_leg() and frees the associated memory. Because the return value of relay_send_command_from_edge() is not checked by the caller, the failure goes undetected, and the caller subsequently writes to the now-freed memory (the current leg pointer), resulting in a NULL write-after-free and process crash. The attack vector is network-based with high complexity and requires no privileges or user interaction (GitHub Advisory, Tor ChangeLog).

Impact

Successful exploitation causes the Tor process to crash, resulting in a denial of service for any relay, bridge, or client running an affected version. There is no confidentiality impact, and integrity impact is assessed as low. Availability is the primary concern, as a crashed Tor node would disrupt anonymized traffic routing and could degrade the broader Tor network if exploited at scale against relay infrastructure (GitHub Advisory).

Exploitabilité

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The EPSS score is 0.0, indicating very low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires high attack complexity, as an attacker must be able to trigger a specific failure condition during CONFLUX_SWITCH cell transmission (GitHub Advisory).

Indicateurs de compromis

  • Process: Unexpected crashes or restarts of the tor process, particularly on nodes with CONFLUX (multi-path circuit) functionality enabled.
  • Logs: Tor log entries indicating circuit closure errors or segmentation faults around CONFLUX_SWITCH cell processing; crash dump files generated by the Tor process.
  • Network: Anomalous patterns of failed CONFLUX_SWITCH cell transmissions observed in Tor relay traffic logs.

Atténuation et solutions de contournement

Upgrade Tor to version 0.4.9.9 or later, which contains the fix for this vulnerability. No configuration-based workaround is documented; upgrading is the recommended and only confirmed remediation. Operators running Tor relays, bridges, or clients on versions 0.4.8.1-alpha through 0.4.8.x should prioritize this update. Monitor for unusual Tor process crashes as an interim detection measure (Tor ChangeLog, GitHub Advisory).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté Linux Debian Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-77647CRITICAL9.8
  • Linux Debian logoLinux Debian
  • spip
NonOuiAug 20, 2026
CVE-2026-77642HIGH7.5
  • Linux Debian logoLinux Debian
  • tor
NonOuiAug 20, 2026
CVE-2026-77641MEDIUM6.5
  • Linux Debian logoLinux Debian
  • tor
NonOuiAug 20, 2026
CVE-2026-77643MEDIUM4.4
  • Linux Debian logoLinux Debian
  • xapian-core
NonOuiAug 20, 2026
CVE-2026-77648LOW2.2
  • Linux Debian logoLinux Debian
  • glance
NonOuiAug 20, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités