HackerOne Disclosed Reports - 2026-09-10

0 Replies, 1 Views

Logo
Medium
resolved

Conflux-queued zero-length RELAY_END triggers heap out-of-bounds read


Bug reported by Brian Carpenter was disclosed at September 10, 2026, 12:10 pm   |   Out-of-bounds Read

A vulnerability was discovered in Tor that could trigger a heap out-of-bounds read when a zero-length RELAY_END cell was processed on a non-open AP stream. The vulnerability was caused by the way Tor handles these cells, where the reason byte was read before checking the message length. This issue was compounded by Conflux's out-of-order delivery, which could copy the zero-length message into an exact-size heap allocation, leading to the out-of-bounds read.


Logo
Low
resolved

Tor onion service INTRODUCE2 invalid-MAC cells permanently grow service replay cache


Bug reported by Brian Carpenter was disclosed at September 10, 2026, 12:10 pm   |   Uncontrolled Resource Consumption

A vulnerability was discovered in Tor's onion service INTRODUCE2 handling. A remote client could send well-formed INTRODUCE1 cells with an invalid MAC, but a unique byte pattern. The introduction point would forward these cells as INTRODUCE2 to the onion service. The onion service would insert the attacker-controlled encrypted section into the introduction-point replay cache before verifying the INTRODUCE2 MAC. The replay cache was created with no expiration, allowing the attacker to grow it with unauthenticated data until memory pressure or out-of-memory.


[Image: e72398fe92beda2aa80d0329e8b9f4febece7568.gif]



Users browsing this thread: 1 Guest(s)