SUSE alert openSUSE-SU-2025:0373-1 (tor)
From: | opensuse-security@opensuse.org | |
To: | security-announce@lists.opensuse.org | |
Subject: | openSUSE-SU-2025:0373-1: moderate: Security update for tor | |
Date: | Fri, 26 Sep 2025 21:05:19 +0200 | |
Message-ID: | <20250926190519.9BE53FBA1@maintenance.suse.de> | |
Archive-link: | Article |
openSUSE Security Update: Security update for tor ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0373-1 Rating: moderate References: #1250101 Cross-References: CVE-2025-4444 Affected Products: openSUSE Backports SLE-15-SP6 openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for tor fixes the following issues: - 0.4.8.18 * CVE-2025-4444: onion service descriptor resource consumption issue (boo#1250101) - 0.4.8.17 * Minor features and bugfixes * use quantum-resistant MLKEM-768 cipher - tor 0.4.8.16 * fix typo in a directory authority rule file * fix a sandbox issue for bandwidth authority and a conflux issue on the control port * client fix about relay flag usage - tor 0.4.8.14 * bugfix for onion service directory cache * test-network now unconditionally includes IPv6 * Regenerate fallback directories 2025-02-05 * Update the geoip files to 2025-02-05 * Fix a pointer free - tor 0.4.8.13 * Conflux related client circuit building performance bugfix * Fix minor memory leaks * Add STATUS TYPE=version handler for Pluggable Transport - tor 0.4.8.12 * Minor features and bugfixes * See https://gitlab.torproject.org/tpo/core/tor/-/raw/release-... Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2025-373=1 - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-373=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 ppc64le s390x x86_64): tor-0.4.8.18-bp157.2.3.1 tor-debuginfo-0.4.8.18-bp157.2.3.1 tor-debugsource-0.4.8.18-bp157.2.3.1 - openSUSE Backports SLE-15-SP6 (aarch64 ppc64le s390x x86_64): tor-0.4.8.18-bp156.2.3.1 References: https://www.suse.com/security/cve/CVE-2025-4444.html https://bugzilla.suse.com/1250101