Gentoo alert 202608-32 (Tor)
| From: | glsamaker@gentoo.org | |
| To: | gentoo-announce@lists.gentoo.org | |
| Subject: | [gentoo-announce] [ GLSA 202608-32 ] Tor: Multiple Vulnerabilities | |
| Date: | Sat, 29 Aug 2026 08:15:03 -0000 | |
| Message-ID: | <178799130404.1.11666862452606660631@3487e0ce30f3> |
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202608-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Tor: Multiple Vulnerabilities Date: August 29, 2026 Bugs: #965987, #969415, #971568, #974279, #976637, #977978, #978087 ID: 202608-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been found in Tor, the worst of which could allow remote code execution. Background ========== Tor is an implementation of second generation Onion Routing, a connection-oriented anonymizing communication service. Affected packages ================= Package Vulnerable Unaffected ----------- ------------ ------------ net-vpn/tor < 0.4.9.11 >= 0.4.9.11 Description =========== Multiple vulnerabilities have been discovered in Tor. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Tor users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=net-vpn/tor-0.4.9.11" References ========== [ 1 ] TROVE-2025-014 [ 2 ] TROVE-2025-015 [ 3 ] TROVE-2025-016 [ 4 ] TROVE-2026-003 [ 5 ] TROVE-2026-004 [ 6 ] TROVE-2026-006 [ 7 ] TROVE-2026-007 [ 8 ] TROVE-2026-008 [ 9 ] TROVE-2026-009 [ 10 ] TROVE-2026-010 [ 11 ] TROVE-2026-011 [ 12 ] TROVE-2026-013 [ 13 ] TROVE-2026-014 [ 14 ] TROVE-2026-015 [ 15 ] TROVE-2026-017 [ 16 ] TROVE-2026-018 [ 17 ] TROVE-2026-019 [ 18 ] TROVE-2026-020 [ 19 ] TROVE-2026-021 [ 20 ] TROVE-2026-025 [ 21 ] TROVE-2026-026 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202608-32 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2026 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmqSlQcbFIAAAAAABAAO bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZ6NUP/Aj5a52Pd8UentwNMUts Lf2fijS9VJZddgkkllJDp1JYUypXTI+mq77AcHgIYR3FdJvV5LRkqgJ4Pt0GGNFu 2B4r4hjm5JAwBr9oQkPNMDDSq7shAyQ2T8Y4hFzMn43en5ZwEcSWslvuW429p1R1 b9LlDmx3YkUizZjqGhKlj1y8HNijoPrutrX6A621+lBOJLS97TVjrgUumbjihx0s qreudXFlJ8LpCMfqc0N6Ac3bwE0EEQuBrXL8wA20Ms+c/sJcFlCXredZI1H5rO0K 0bTIDnhV1P1vlHaSONVwQoPb8kFzCgT2IWDDeI2KL3HIB1URVdRLcD0+1vRVNql+ 8K4s3LnQUF7q1MFHV8S+1Y55YMJribg7a0fheL87TAVSi8+ZhwkVm8lpHcDIugtL 0Wq4ty39R8EEs8DGllolJ1sd+cjfej1gLTDR3mhtNYgkd3ZE53p/qzGwXLMj996v Vb4dLo+6iSAW8SoiXisMi19idzEKtn1+sZsTYIb+H8d83SUMtKTDg8yrFge2PZS5 rvTJepkbYRfDy6xcikGCiDL3j2Fz6/qbJP1pwW95V2SFOu76YuQerr+4g9f01GIC woVnW4suGxOCYQzVmb9B2oyANwO3Xn2onmybdffjcomS1EfLz2YdVggNpDx3o0Uc EwZXSLh0JBDd38XAAMZRy/pD =jtbZ -----END PGP SIGNATURE-----
