VDB

GCVE-110-MAGEIA-2021-293

GCVE-110-MAGEIA-2021-293
Advisory Published
Vulnetix · Advisory published June 28, 2021
Don't allow relays to spoof RELAY_END or RELAY_RESOLVED cell on half-closed streams. Previously, clients failed to validate which hop sent these cells: this would allow a relay on a circuit to end a stream that wasn't actually built with it (CVE-2021-34548). hashtable-based CPU denial-of-service attack against relays (CVE-2021-34549). out-of-bounds memory access in v3 onion service descriptor parsing (CVE-2021-34550). See also upstream release notes for included other bugfixes. This package also fixes an error in tor package's un-install script (mga#29158).

Affected Products

VendorProductVersionsPlatforms
Mageiator0 (affected), 0.3.5.15-1.1.mga8 (unaffected)
Mageiator0 (affected), 0.3.5.15-1.1.mga7 (unaffected)

Browse GCVE Records

73,877 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›