Impact
Tor before 0.4.9.11 contains a race condition that allows a rendezvous point to impersonate the onion service a client is trying to reach. This flaw can enable a malicious relay to perform a man‑in‑the‑middle attack, exposing the client to credential theft or malicious content. The weakness stems from concurrent access to shared data structures, as identified by CWE-362.
Affected Systems
Affected systems include Tor 0.4.9.10 and earlier releases from the Torproject. No specific version range beyond the kernel is listed; administrators should treat all releases prior to 0.4.9.11 as vulnerable.
Risk and Exploitability
The CVSS score of 8.9 indicates a high severity, and the absence of an EPSS value does not imply low risk; the vulnerability is still exploitable under the right circumstances. It is not currently listed in the CISA KEV catalog, but the potential for a compromised rendezvous point to impersonate an onion service constitutes a serious threat. The probability of exploitation depends on the ability to control or influence a rendezvous point, which is plausible in networks where the adversary can run or compromise relays.
OpenCVE Enrichment