Impact
The vulnerability causes an out-of-bounds write when Tor parses a consensus or a detached signature that contains an unexpected signature digest type, potentially corrupting memory and leading to a process crash or unpredictable behavior. Although most Tor roles may only experience a minor disruption, directory authorities—whose gateways validate consensus data—could be severely impacted.
Affected Systems
Tor Project's Tor software is affected. Any Tor installation with a version earlier than 0.4.9.9 is vulnerable. No specific workarounds are documented; the fix is included in Tor version 0.4.9.9 and later.
Risk and Exploitability
The CVSS score is 7.5, indicating a high severity vulnerability. EPSS data is unavailable, so the exploitation probability is unknown; the issue is not listed in CISA's KEV catalog. The likely attack vector is remote: an attacker can craft a malicious consensus or detached signature with an unexpected digest type and deliver it over the network to a Tor node, especially a directory authority, which then parses the data and triggers the buffer write. This suggests that vulnerabilty can be exploited when the attacker has network access to a vulnerable Tor instance. Overall risk is moderate‑high.
OpenCVE Enrichment