Upcoming C-tor security release - 0.4.9.12
Tor Project announces an upcoming C-tor security release 0.4.9.12 addressing a security flaw.
The Tor Project forum posted a heads-up for an upcoming security release of the C implementation of Tor, version 0.4.9.12. The post text contains no additional details about the vulnerability, affected versions, or exploitation status. The announcement signals that users should prepare for a patch.
The GNU C Library security advisories update for 2026-09-14
glibc advisory GLIBC-SA-2026-0017 discloses a buffer overflow in strfmon/strfmon_l affecting versions 2.38 through 2.44.
The GNU C Library published security advisories including GLIBC-SA-2026-0017, a buffer overflow in strfmon and strfmon_l. Calling these functions with right-justified width padding conversions can write past the end of the caller-supplied output buffer in glibc 2.38 to 2.44. Exploitation requires an application code path that calls strfmon with attacker-influenced parameters.