Просмотр исходного кода

update tor from 0.4.9.12-r0 to 0.4.9.13-r0

security release (TROVE-2026-051, TROVE-2026-058), relevant changes:
- onion service: relaunch failed service-side rendezvous circuits exactly
  once instead of twice (exponential circuit builds per INTRODUCE2 on
  repeated failures)
- onion service: rotate intro point if INTRODUCE2 replay cache is full
- fix use-after-free when TCP connection succeeds immediately but TLS
  handshake fails
- fix memory corruption / double-free / null pointer dereference with
  some reverse DNS virtual address configurations
- stop blaming guards for circuit, stream & directory-request failures
- HSDirs: rate limit "invalid signature length" log messages
- controller: no longer seg fault on SETCIRCUITPURPOSE without arguments

https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ReleaseNotes

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Fabian Peter Hammerle 1 неделя назад
Родитель
Сommit
2468fbc2f1
1 измененных файлов с 1 добавлено и 1 удалено
  1. 1 1
      Dockerfile

+ 1 - 1
Dockerfile

@@ -6,7 +6,7 @@ ARG GETTEXT_PACKAGE_VERSION=1.0-r0
 # https://gitweb.torproject.org/tor.git/plain/ChangeLog
 # https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ReleaseNotes
 # https://git.alpinelinux.org/aports/log/community/tor?h=3.24-stable
-ARG TOR_PACKAGE_VERSION=0.4.9.12-r0
+ARG TOR_PACKAGE_VERSION=0.4.9.13-r0
 RUN apk add --no-cache \
         tor=$TOR_PACKAGE_VERSION \
         gettext-envsubst=$GETTEXT_PACKAGE_VERSION \