Impact
Tor before 0.4.9.11 contains a use‑after‑free flaw in the handling of conflux objects when a recovery leg revives a set whose last leg has already been closed. This causes the client to crash, representing a denial‑of‑service attack. The weakness is categorized as CWE‑911, a use‑after‑free flaw.
Affected Systems
Tor users running any version older than 0.4.9.11 are vulnerable. The affected product is Tor from torproject, and all releases before 0.4.9.11 should be considered.
Risk and Exploitability
The CVSS score is 5.9, indicating moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the flaw by acting as a malicious exit node that sends a crafted circuit to the client, triggering the recovery leg logic and causing a crash. The exploit requires network proximity and the ability to control the exit node, making remote exploitation feasible from any exit node the client is willing to accept.
OpenCVE Enrichment