🛡️ openSUSE-SU-2022:10209-1 — tor
Description
Security update for tor
This update for tor fixes the following issues:
tor 0.4.7.11:
- Improve security of DNS cache by randomly clipping the TTL
value (boo#1205307, TROVE-2021-009)
- Improved defenses against network-wide DoS, multiple counters
and metrics added to MetricsPorts
- Apply circuit creation anti-DoS defenses if the outbound
circuit max cell queue size is reached too many times. This
introduces two new consensus parameters to control the queue
size limit and number of times allowed to go over that limit.
- Directory authority updates
- IPFire database and geoip updates
- Bump the maximum amount of CPU that can be used from 16 to 128.
The NumCPUs torrc option overrides this hardcoded maximum.
- onion service: set a higher circuit build timeout for opened
client rendezvous circuit to avoid timeouts and retry load
- Make the service retry a rendezvous if the circuit is being
repurposed for measurements
Affected software
openSUSE-SU-2022:10209-1 is recorded against 1 package.
- tor (fixed in 0.4.7.11-bp154.2.9.1)
Timeline and source
Published on 20 November 2022. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| tor | — | 0.4.7.11-bp154.2.9.1 |
References
Similar Threats
- Low CVE-2026-44597
- Low CVE-2026-44599
- Low CVE-2026-44600
- Low CVE-2026-44601
- Unknown DEBIAN-CVE-2026-44597
Free Vulnerability Check
Is your site affected by openSUSE-SU-2022:10209-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2022:10209-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.