Fedora 43 and 44 Tor Updates Address Denial of Service Vulnerabilities

Fedora 43 and 44 Tor Updates Address Denial of Service Vulnerabilities

First seen 26 May 2026, 15:30 UTC Linuxsecurity 92% similarity 57.9

Article Content

Browse articles
ThreatCluster

On May 15, 2026, Fedora released updates for Tor in versions 43 and 44 to address multiple denial of service vulnerabilities. These updates fix five CVEs: CVE-2026-44597, CVE-2026-44599, CVE-2026-44600, CVE-2026-44601, CVE-2026-44602, and CVE-2026-44603, all published on May 7, 2026. The vulnerabilities could allow attackers to exploit Tor's handling of CERT and BEGIN cells, potentially leading to client crashes or service disruptions. Affected systems include all Fedora installations running the Tor service. Users are advised to update their systems using the 'dnf' update program to mitigate these risks. The updates are critical for maintaining the integrity and availability of the Tor network.

Key Points: • Fedora released critical updates for Tor on May 15, 2026, addressing multiple CVEs. • The vulnerabilities could lead to denial of service attacks, impacting Tor users. • Users are urged to apply updates immediately to secure their systems.

ThreatCluster AI

Timeline

2026-05-07
CVE-2026-44597 published
CVE-2026-44597 details a denial of service vulnerability due to out-of-bounds read in Tor.
Linuxsecurity
2026-05-07
CVE-2026-44599 published
CVE-2026-44599 involves low integrity impact via directory message manipulation in Tor.
Linuxsecurity
2026-05-07
CVE-2026-44600 published
CVE-2026-44600 describes a denial of service vulnerability via malformed CERT cells.
Linuxsecurity
2026-05-07
CVE-2026-44601 published
CVE-2026-44601 details a client crash due to double close of a circuit in Tor.
Linuxsecurity
2026-05-07
CVE-2026-44602 published
CVE-2026-44602 outlines a denial of service vulnerability via out-of-order CERT cells.
Linuxsecurity
2026-05-07
CVE-2026-44603 published
CVE-2026-44603 describes a denial of service vulnerability via malformed BEGIN cells.
Linuxsecurity
2026-05-15
Fedora updates Tor to fix vulnerabilities
Fedora released updates for Tor to address multiple denial of service vulnerabilities, urging users to upgrade.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story