Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package tor for openSUSE:Factory checked in at 2026-09-28 10:39:07 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/tor (Old) and /work/SRC/openSUSE:Factory/.tor.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "tor" Mon Sep 28 10:39:07 2026 rev:137 rq:1380293 version:0.4.9.13 Changes: -------- --- /work/SRC/openSUSE:Factory/tor/tor.changes 2026-08-24 12:16:49.032101165 +0200 +++ /work/SRC/openSUSE:Factory/.tor.new.383539/tor.changes 2026-09-28 10:40:25.095783295 +0200 @@ -1,0 +2,94 @@ +Fri Sep 25 03:30:55 UTC 2026 - Bernhard Wiedemann <[email protected]> + +- Update to 0.4.9.13 + * Major bugfixes (security): + - Avoid possible memory corruption, double-free, and null + pointer dereference bugs that could occur with some reverse DNS + virtual address configurations (TROVE-2026-051) + - Avoid cacheing DNS PTR responses when DNS caching is disabled + (TROVE-2026-050) + * Major bugfixes (client stream handling): + - Stop trying to reattach BEGIN_DIR directory streams (TROVE-2026-052) + * Major bugfixes (client, guard): + - Stop blaming guards for circuit, stream, directory-request, and + generic channel-close failures, and instead only record guard + failure once per unsuccessful outgoing connection establishment. + This also covers directory guards, synchronous failures, and proxy + or pluggable transport paths. + This fixes (TROVE-2026-030, TROVE-2026-038, TROVE-2026-041) + * Major bugfixes (connection handling): + - Fix a use-after-free when a TCP connection succeeds immediately + but starting its TLS handshake fails (TROVE-2026-056) + * Major bugfixes (onion service): + - A service-side rendezvous circuit that failed before reaching the + rendezvous point was relaunched twice (once when marked for close + and once more when freed), producing two concurrent circuits that + carried the same rendezvous cookie and key material and, with + repeated failures, 2^(N+1)-1 circuit builds per INTRODUCE2 instead + of N+1. (TROVE-2026-058) + - Rotate intro point at the service if the INTRODUCE2 replay cache + is at capacity. (TROVE-2026-012) + * Major bugfixes (onion service, TROVE): + - Reject INTRODUCE2 cells containing a zeroed rendezvous point ntor + onion key (TROVE-2026-030) + * Major bugfixes (relay): + - Remove circuits waiting for a channel from the pending channel + list as soon as they are marked for close instead of waiting until + they are freed. Fixes bug 41393 + * Major bugfixes (stream isolation): + - When a client establishes a circuit to an onion service, but the + original stream had already closed, we were mistakenly clearing + the isolation parameters on that circuit, allowing it to be reused + by a future stream from a different isolation context. A malicious + onion service or HSDir relay could use this technique to break + first-party isolation (FPI) in Tor Browser (TROVE-2026-053) + * Minor features (HSDirs): + - Rate limit "Service descriptor has an invalid signature length" + messages at HSDir relays. This step only makes a flooding attack + more tolerable; it does not resolve or explain a flooding attack. + Improves the situation for ticket 41339. Bugfix on 0.3.0.1-alpha. + * Minor bugfixes (client, stream handling): + - When an exit or onion service answers a BEGIN with an END cell + whose reason byte is 0, report the stream to the application and + to controllers as a generic remote failure. Previously reason 0 + turned into the internal "succeeded" value, so SOCKS clients got a + success reply, HTTP CONNECT clients got "200 OK", and controllers + got a STREAM SUCCEEDED event for a stream that never connected. + Also fix the formatting of unrecognized END reasons in controller + STREAM events. Fixes bug 41353 + * Minor bugfixes (controller): + - No longer seg fault if a local authenticated controller connection + asks for SETCIRCUITPURPOSE with no arguments. Fixes bug 41332 + * Minor bugfixes (directory parsing): + - When parsing an authority certificate with an explicit length, do + not skip trailing whitespace beyond that length. All current + callers pass NUL-terminated strings, so no bug was reachable in + practice. Fixes bug 41378 + * Minor bugfixes (metrics): + - Fix an off-by-one in metrics_store_hist_entry_get_value() that + read one histogram bucket past the end of the array when asked for + a bucket boundary that does not exist. No in-tree caller currently + passes such a value. Fixes bug 41376 + * Minor bugfixes (pluggable transports): + - Bridge clients or bridge relays no longer mangle memory the second + time a pluggable transport or socksproxy configuration is changed, + such as by setconf, resetconf, or sighup. Fixes bug 41375 + +- Update to 0.4.9.12 + * Major bugfixes (security): + + Do not purge memory for OOM from within low-level code. + (TROVE-2026-043) + + Fix a bug about reusable router descriptor (TROVE-2026-034) + + Fix a use-after-free around AutomapHostsOnResolve (TROVE-2026-036) + + Negotiate CGO cryptography with every hop that supports it (TROVE-2026-033) + + Reject certain CC_RESPONSE extensions (boo#1279897, CVE-2026-87724,TROVE-2026-032) + + Validate DNS names for complience (TROVE-2026-033) + * Major bugfixes (conflux, client, stream isolation): + + Keep the stream isolation state in sync of a linked conflux set on + every leg when attaching new streams (TROVE-2026-040) + * Minor features around directory authorities + * Removed features: + - Tor clients no longer accept consensus instructions to downgrade + the congestion control algorithm = defense in depth + +------------------------------------------------------------------- Old: ---- tor-0.4.9.11.tar.gz tor-0.4.9.11.tar.gz.sha256sum tor-0.4.9.11.tar.gz.sha256sum.asc New: ---- tor-0.4.9.13.tar.gz tor-0.4.9.13.tar.gz.sha256sum tor-0.4.9.13.tar.gz.sha256sum.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ tor.spec ++++++ --- /var/tmp/diff_new_pack.MYTefu/_old 2026-09-28 10:40:26.550844310 +0200 +++ /var/tmp/diff_new_pack.MYTefu/_new 2026-09-28 10:40:26.552844394 +0200 @@ -20,11 +20,12 @@ %define toruser %{name} %define torgroup %{name} Name: tor -Version: 0.4.9.11 +Version: 0.4.9.13 Release: 0 Summary: Anonymizing overlay network for TCP (The onion router) License: BSD-3-Clause URL: https://www.torproject.org/ +#Git-Clone: https://gitlab.com/torproject/tor Source0: https://www.torproject.org/dist/%{name}-%{version}.tar.gz # https://support.torproject.org/little-t-tor/verify-little-t-tor/ Source2: tor.keyring ++++++ tor-0.4.9.11.tar.gz -> tor-0.4.9.13.tar.gz ++++++ /work/SRC/openSUSE:Factory/tor/tor-0.4.9.11.tar.gz /work/SRC/openSUSE:Factory/.tor.new.383539/tor-0.4.9.13.tar.gz differ: char 12, line 1 ++++++ tor-0.4.9.11.tar.gz.sha256sum -> tor-0.4.9.13.tar.gz.sha256sum ++++++ --- /work/SRC/openSUSE:Factory/tor/tor-0.4.9.11.tar.gz.sha256sum 2026-08-24 12:16:48.995099847 +0200 +++ /work/SRC/openSUSE:Factory/.tor.new.383539/tor-0.4.9.13.tar.gz.sha256sum 2026-09-28 10:40:25.033780695 +0200 @@ -1 +1 @@ -2e6c1720118c812acf0079fd47cf91b6bfaba5d766c321c4d3d2a28d6a11a8ed tor-0.4.9.11.tar.gz +5e748d3272cdf44a7d7741173f371c8def3d96eecb77e93c89c50663ce9cc792 tor-0.4.9.13.tar.gz
