Resource management error in Tor - CVE-2021-34549
Published: June 20, 2021
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the naive unkeyed hash function. A remote attacker can construct circuits with chosen circuit IDs, to create collisions and make the hash table inefficient, resulting in denial of service condition.
Affected software
Gentoo Linux
Arch Linux
Fedora
tor (Debian package)
tor
How to mitigate CVE-2021-34549
tor (Debian package) - update to 0.3.5.15-1
tor - addressed in versions 0.3.5.15-1.el7, 0.4.5.9-1.el8, 0.4.5.9-1.fc33, 0.4.5.9-1.fc34, 0.4.5.10-1.el8