CVE-2017-8822: Debian Linux

Low severity, CVSS 3.7. EPSS: 0.9% chance of exploitation in the next 30 days.

In Tor before 0.2.5.16, 0.2.6 through 0.2.8 before 0.2.8.17, 0.2.9 before 0.2.9.14, 0.3.0 before 0.3.0.13, and 0.3.1 before 0.3.1.9, relays (that have incompletely downloaded descriptors) can pick themselves in a circuit path, leading to a degradation of anonymity, aka TROVE-2017-012.

Affected products

  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Tor Project Tor: before 0.2.5.16 (fixed in 0.2.5.16); from 0.2.6, before 0.2.8.17 (fixed in 0.2.8.17); from 0.2.9, before 0.2.9.14 (fixed in 0.2.9.14); from 0.3.0, before 0.3.0.13 (fixed in 0.3.0.13); from 0.3.1, before 0.3.1.9 (fixed in 0.3.1.9)

Published 2017-12-03. Last modified 2026-06-17.