CVE-2026-77587
Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.22%
- CWE
- CWE-911
- Published
- 2026-08-20
- Last modified
- 2026-08-25
Affected products
- torproject Tor
Weakness type
Related vulnerabilities
- CVE-2026-49419 — Jail reference count underflow
- CVE-2026-19380 — Mullvad wireguard.sys IOCTL AdapterState reference count
- CVE-2024-45783 — Grub2: fs/hfs+: refcount can be decremented twice
- CVE-2024-46972 — GPU DDK - Security: Reference count overflow in pvr_sync_rollback_export_fence
- CVE-2024-43102 — umtx Kernel panic or Use-After-Free
- CVE-2023-6270 — Kernel: aoe: improper reference count leads to use-after-free vulnerability
- CVE-2023-5633 — Kernel: vmwgfx: reference count issue leads to use-after-free in surface handling
- CVE-2023-2019 — A flaw was found in the Linux kernel's netdevsim device driver, within the scheduling of events....