Security Advisory

CVE-2026-77640

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-20 21:02:36
Last updated 2026-08-21 20:08:38
Assigner mitre
CVSS score 3.7
State PUBLISHED

Description

tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer and retried forever. Fixed by returning TOR_COMPRESS_ERROR in that case so the caller can abort cleanly. This is TROVE-2026-021.