CVE-2026-77587
EUVD-2026-6359320.08.2026, 21:17
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| torproject | tor | 𝑥 < 0.4.9.11 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
- CWE-911 - Improper Update of Reference CountThe software uses a reference count to manage a resource, but it does not update or incorrectly updates the reference count.
- CWE-416 - Use After FreeReferencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.