"""
@@ -1,3 +1,136 @@
+Changes in version 0.4.9.14 - 2026-10-07
+ Another week, another security release. This again contains major bugfixes
+ related to high severity issues. The fixes affect all Tor components: relay,
+ client, onion service and authority. We strongly recommend upgrading as soon
+ as possible.
+
+ o Major bugfixes (conflux, relay, security):
+ - Only accept a CONFLUX_LINK cell on a plain OR circuit, and refuse
+ to turn a (pending) conflux leg into an introduction or rendezvous
+ point. Previously a client could link a rendezvous-point circuit
+ into a conflux set and then, with a forged sequence number in the
+ LINK cell, make the relay tear the set down from inside the
+ rendezvous splice, triggering a fatal assertion in
+ assert_circuit_ok(). Also reject a LINK/LINKED cell whose
+ last_seqno_recv is above what we ever sent on the set. Fixes bug
+ 41328; bugfix on 0.4.8.1-alpha.
+
+ o Major bugfixes (security):
+ - Correctly copy the MiddleOnly flag from routerstatuses to node
+ objects. Without this fix, the MiddleOnly flag was ignored on non-
+ authorities, and clients could use MiddleOnly relays for
+ inappropriate roles in onion service circuits. Fixes bug 41410;
+ bugfix on 0.4.8.15. Tracked as TROVE-2026-067.
+ - Treat a router descriptor as expired if any of its family
+ certificates has expired. Previously, we incorrectly ignored the
+ expiration time of the family certificate. Fixes bug 41413; bugfix
+ on 0.4.9.2-alpha. Tracked as TROVE-2026-062.
+
+ o Major bugfixes (circuit build timeout):
+ - Under certain conditions, the circuit build timeout history could
+ become filled with "abandoned" entries, which would block updating
+ the timeout as network conditions change. This could cause
+ connectivity failure if the timeout value became stuck at a
+ sufficiently low value. Missing first-hop timeout accounting could
+ also prevent the timeout from being reset, when these failures
+ happen at the first hop of the circuit. We've corrected the first-
+ hop accounting, and have fixed two sources of excessive abandoned
+ timeout entries, and added additional reset handling when the
+ timeout history becomes full of abandoned timeout measurements.
+ We've also added diagnostic log messages to help detect any
+ potential remaining cases of timeout miscounting and abandonment
+ accumulation. Fixes bug 41420; bugfix on 0.2.2.14-alpha.
+
+ o Major bugfixes (circuit, channel):
+ - Cancelling a circuit before its first hop completed would cause
+ Tor to stop using a working guard connection for new circuits and
+ abort unrelated pending directory requests. These cancellations
+ could also be triggered remotely, causing additional TLS
+ connections to the same guard that could aid traffic analysis. DoS
+ conditions and/or overly short circuit build timeouts could also
+ cause unnecessary connection replacement, at the exact time when
+ additional connection load would be most harmful. We've restricted
+ this recovery behavior to actual first-hop timeouts, allowing at
+ least the longer of the measurement timeout and the initial
+ preserve recovery from stalled connections without changing guard
+ reachability. Fixes bug 41412; bugfix on 0.1.1.10-alpha.
+
+ o Major bugfixes (directory authority):
+ - When enforcing AuthDirMaxServersPerAddr, only count relays that we
+ have found reachable at that address and stop resetting the uptime
+ history of relays over the limit. This is TROVE-2026-064. Fixes
+ bug 41405; bugfix on 0.2.4.10-alpha.
+
+ o Major bugfixes (onion service client):
+ - When an introduction point NACKs our INTRODUCE1 and we re-extend
+ the same circuit to another introduction point, update the
+ circuit's introduction point authentication key. Fixes bug 41437;
+ bugfix on 0.3.2.1-alpha.
+
+ o Major bugfixes (onion services):
+ - Fix the behavior of HiddenServiceAllowUnknownPorts, which aims to
+ slow down port-scanning on onion services. It was correct as
+ implemented in Tor 0.2.6.3-alpha (ticket 14084), but during the
+ transition to v3 onion services we accidentally inverted its
+ logic. Now onion services will resume closing the client's circuit
+ if it asks to connect to an unconfigured port. Fixes bug 41435;
+ bugfix on 0.3.2.1-alpha.
+
+ o Minor features (fallbackdir):
+ - Regenerate fallback directories generated on October 07, 2026.
+
+ o Minor features (geoip data):
+ - Update the geoip files to match the IPFire Location Database, as
+ retrieved on 2026/10/07.
+
+ o Minor bugfixes (client):
+ - Stop logging a misleading backtrace when the user uses
+ AutomapHostsOnResolve combined with a MapAddress line that maps to
+ a .exit address. Fixes bug 41418; bugfix on 0.3.2.1-alpha.
+
+ o Minor bugfixes (compilation):
+ - Only define the SYS_SECCOMP fallback when using libseccomp. This
+ avoids redefining a system provided macro in builds with
+ --disable-seccomp. Bugfix on 0.4.9.4-rc.
+
+ o Minor bugfixes (compression):
+ - Harden the lzma2 streaming implementation against some kinds of
+ infinite-loop denial of service attacks. This isn't actually a
+ security vulnerability in Tor, since we never use lzma2 in
+ streaming mode. Fixes bug 41324; bugfix on 0.3.1.1-alpha.
+
+ o Minor bugfixes (consensus diff):
+ - Reject consensus diffs at exactly the line-count threshold and
+ above. Previously, a diff with exactly the threshold number of
+ lines passed the limit check. Bugfix on 0.4.9.12.
+
+ o Minor bugfixes (directory authority):
+ - When the votes select an unsupported consensus method, fall back
+ to the newest method supported by the current configuration. This
+ fixes the issue that authorities with AuthDirSupport048Clients
+ enabled could still pick consensus method 36 if the method in the
+ votes was below. Bugfix on 0.4.9.12.
+
+ o Minor bugfixes (fuzzing):
+ - Fix a false positive from fuzzing code caused by an earlier
+ security fix for consensus-diff application. Fixes bug 41385;
+ bugfix on 0.4.9.12.
+
+ o Minor bugfixes (memory management):
+ - Preserve cleanup requests raised during reclamation while memory
+ remains over the limit, leaving further cleanup to the main loop.
+ Bugfix on 0.4.9.12.
+ - Recompute memory usage after cache cleanup so that relay END cells
+ queued while expiring pending DNS resolutions count toward circuit
+ memory reclamation. Bugfix on 0.3.5.1-alpha.
+
+ o Minor bugfixes (onion services):
+ - Stop memory-leaking an address string for every stream begin
+ request to an onion service unix domain socket ("unix:")
+ destination. Fixes bug 41434; bugfix on 0.2.6.3-alpha.
"""sam
signature.asc
Description: PGP signature
