Linuxsecurity Fedora 43 and 44 Tor Updates Address Denial of Service Vulnerabilities
Article Content
- •Fedora released critical updates for Tor on May 15, 2026, addressing multiple CVEs.
- •The vulnerabilities could lead to denial of service attacks, impacting Tor users.
- •Users are urged to apply updates immediately to secure their systems.
On May 15, 2026, Fedora released updates for Tor in versions 43 and 44 to address multiple denial of service vulnerabilities. These updates fix five CVEs: CVE-2026-44597, CVE-2026-44599, CVE-2026-44600, CVE-2026-44601, CVE-2026-44602, and CVE-2026-44603, all published on May 7, 2026. The vulnerabilities could allow attackers to exploit Tor's handling of CERT and BEGIN cells, potentially leading to client crashes or service disruptions. Affected systems include all Fedora installations running the Tor service. Users are advised to update their systems using the 'dnf' update program to mitigate these risks. The updates are critical for maintaining the integrity and availability of the Tor network.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Fedora and CVE-2026-44597 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…