Impact
Tor before version 0.4.9.12 interprets a CC_RESPONSE extension even when a CC_REQUEST was not previously sent, corrupting the congestion-control state and causing the process to crash. This flaw yields a denial‑of‑service for the Tor daemon and can interrupt the functioning of Tor circuits that rely on that controller.
Affected Systems
The Tor daemon released by the Tor Project with versions earlier than 0.4.9.12 is affected, as the bug exists in the codebase up to and including 0.4.9.11.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, implying no widespread exploitation has been documented. The likely attack vector is remote, whereby an attacker can transmit a malformed CC_RESPONSE packet over the network to trigger the crash.
OpenCVE Enrichment