CVE-2021-38385
NixOS vulnerability analysis and mitigation

Overview

CVE-2021-38385 affects Tor versions before 0.3.5.16, 0.4.5.10, and 0.4.6.7. The vulnerability involves a mishandling of the relationship between batch-signature verification and single-signature verification, which can lead to a remote assertion failure. This vulnerability is also tracked as TROVE-2021-007 (Tor Blog).

Technical details

The vulnerability stems from a behavior mismatch between batch-signature verification code and single-signature verification code in Tor's cryptographic implementation. The issue was discovered by Henry de Valence and affects the Ed25519 cryptographic functionality. The vulnerability has a CVSS v3.1 base score of 7.5 (HIGH), with a vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (NVD).

Impact

The vulnerability could allow remote attackers to trigger an assertion failure, leading to a denial of service attack. This affects all Tor installations whether running as a client, relay, or onion service (Tor Blog).

Mitigation and workarounds

The vulnerability was fixed in Tor versions 0.3.5.16, 0.4.5.10, and 0.4.6.7. Users running earlier versions should upgrade to one of these patched versions. The fix involves disabling the unused batch verification feature of ed25519-donna (Tor Blog, Ubuntu Notice).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-48606HIGH7.8
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48625HIGH7
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48608MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-48569MEDIUM5.5
  • NixOSNixOS
  • android
NoNoDec 08, 2025
CVE-2025-65799MEDIUM4.3
  • NixOSNixOS
  • memos
NoYesDec 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management