{"id":"CVE-2021-38385","details":"Tor before 0.3.5.16, 0.4.5.10, and 0.4.6.7 mishandles the relationship between batch-signature verification and single-signature verification, leading to a remote assertion failure, aka TROVE-2021-007.","modified":"2026-05-18T05:53:05.790419292Z","published":"2021-08-30T05:15:07.237Z","related":["openSUSE-SU-2021:1169-1","openSUSE-SU-2021:1178-1","openSUSE-SU-2021:1192-1","openSUSE-SU-2024:11469-1"],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*"],"source":"CPE_FIELD","vendor_product":"torproject:tor","extracted_events":[{"fixed":"0.3.5.16"}]}]},"references":[{"type":"ADVISORY","url":"https://blog.torproject.org"},{"type":"ADVISORY","url":"https://blog.torproject.org/node/2062"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202305-11"},{"type":"REPORT","url":"https://bugs.torproject.org/tpo/core/tor/40078"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/torproject/tor","events":[{"introduced":"0"},{"fixed":"15139a1c00124a6e9a65999ee25af01f890d7c3c"},{"fixed":"fd74f7628eba25258817addb059512cd0eef1d80"},{"fixed":"31728f4ad386042d3088f015e28f15d91ae3e283"}],"database_specific":{"source":"CPE_FIELD","cpe":"cpe:2.3:a:torproject:tor:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.3.5.16"},{"introduced":"0.4.0.0"},{"fixed":"0.4.5.10"},{"introduced":"0.4.6.0"},{"fixed":"0.4.6.7"}]}}],"versions":["tor-0.4.6.6","tor-0.3.5.15","tor-0.4.5.9","tor-0.4.6.5","tor-0.4.6.4-rc","tor-0.4.6.3-rc","tor-0.4.5.8","tor-0.4.6.2-alpha","tor-0.4.6.1-alpha","tor-0.4.5.7","tor-0.3.5.14","tor-0.4.5.6","tor-0.3.5.13","tor-0.4.5.5-rc","tor-0.4.5.4-rc","tor-0.4.5.3-rc","tor-0.4.5.2-alpha","tor-0.4.6.0-alpha-dev","tor-0.3.5.12","tor-0.4.5.1-alpha","tor-0.3.5.11","tor-0.4.5.0-alpha-dev","tor-0.3.5.10","tor-0.4.4.0-alpha-dev","tor-0.4.3.2-alpha","tor-0.4.3.1-alpha","tor-0.3.5.9","tor-0.4.3.0-alpha-dev","tor-0.4.2.2-alpha","tor-0.4.2.1-alpha","tor-0.4.1.2-alpha","tor-0.4.1.1-alpha","tor-0.3.5.8","tor-0.4.1.0-alpha-dev","tor-0.4.0.1-alpha","tor-0.3.5.7","tor-0.3.5.6-rc","tor-0.3.5.5-alpha","tor-0.3.5.4-alpha","tor-0.3.5.3-alpha","tor-0.3.5.2-alpha","tor-0.3.5.1-alpha","tor-0.3.5.0-alpha-dev","tor-0.3.4.2-alpha","tor-0.3.4.1-alpha","tor-0.3.4.0-alpha-dev","tor-0.3.3.2-alpha","tor-0.3.3.1-alpha","tor-0.3.3.0-alpha-dev","tor-0.3.2.2-alpha","tor-0.3.2.1-alpha","tor-0.3.1.3-alpha","tor-0.3.1.2-alpha","tor-0.3.1.1-alpha","tor-0.3.0.3-alpha","tor-0.3.0.2-alpha","tor-0.3.0.1-alpha","tor-0.2.9.4-alpha","tor-0.2.9.3-alpha","tor-0.2.9.2-alpha","tor-0.2.9.1-alpha","tor-0.2.9.0-root","tor-0.2.8.2-alpha","tor-0.2.8.1-alpha","tor-0.2.7.3-rc","tor-0.2.7.2-alpha","tor-0.2.7.1-alpha","tor-0.2.7.0-root","tor-0.2.6.3-alpha","tor-0.2.6.2-alpha","tor-0.2.6.1-alpha","tor-0.2.5.5-alpha","tor-0.2.5.4-alpha","tor-0.2.5.3-alpha","tor-0.2.5.2-alpha","tor-0.2.5.1-alpha","tor-0.2.4.10-alpha","tor-0.2.4.9-alpha","tor-0.2.4.8-alpha","tor-0.2.4.7-alpha","tor-0.2.4.6-alpha","tor-0.2.4.5-alpha","tor-0.2.4.4-alpha","tor-0.2.4.3-alpha","tor-0.2.4.2-alpha","tor-0.2.4.1-alpha","tor-0.2.3.17-beta","tor-0.2.3.16-alpha","tor-0.2.3.15-alpha","tor-0.2.3.14-alpha","tor-0.2.3.13-alpha","tor-0.2.3.12-alpha","tor-0.2.3.11-alpha","tor-0.2.3.10-alpha","tor-0.2.3.9-alpha","tor-0.2.3.8-alpha","tor-0.2.3.7-alpha","tor-0.2.3.6-alpha","tor-0.2.3.5-alpha","tor-0.2.3.4-alpha","tor-0.2.3.3-alpha","tor-0.2.3.2-alpha","tor-0.2.3.1-alpha","tor-0.2.2.16-alpha","tor-0.2.2.15-alpha","tor-0.2.2.14-alpha","tor-0.2.2.13-alpha","tor-0.2.2.12-alpha","tor-0.2.2.11-alpha","tor-0.2.2.10-alpha","tor-0.2.2.9-alpha","tor-0.2.2.8-alpha","tor-0.2.2.7-alpha","tor-0.2.2.6-alpha","tor-0.2.2.5-alpha","tor-0.2.2.4-alpha","tor-0.2.2.3-alpha","tor-0.2.2.2-alpha","tor-0.2.2.1-alpha","tor-0.2.1.14-rc","tor-0.2.1.13-alpha","tor-0.2.1.11-alpha","tor-0.2.1.10-alpha","tor-0.2.1.9-alpha","tor-0.2.1.8-alpha","tor-0.2.1.7-alpha","tor-0.2.1.6-alpha","tor-0.2.1.5-alpha","tor-0.2.1.4-alpha","tor-0.2.1.3-alpha","tor-0.2.1.2-alpha","tor-0.2.1.1-alpha","tor-0.2.0.20-rc","tor-0.2.0.19-alpha","tor-0.2.0.18-alpha","tor-0.2.0.17-alpha","tor-0.2.0.16-alpha","tor-0.2.0.15-alpha","tor-0.2.0.14-alpha","tor-0.2.0.13-alpha","tor-0.2.0.12-alpha","tor-0.2.0.11-alpha","tor-0.2.0.10-alpha","tor-0.2.0.9-alpha","tor-0.2.0.8-alpha","tor-0.2.0.7-alpha","tor-0.2.0.6-alpha","tor-0.2.0.5-alpha","tor-0.2.0.4-alpha@11197","tor-0.2.0.3-alpha","tor-0.2.0.2-alpha","tor-0.2.0.1-alpha","tor-0.1.2.9-rc","tor-0.1.2.8-beta","tor-0.1.2.7-alpha","tor-0.1.2.6-alpha","tor-0.1.2.5-alpha","tor-0.1.2.4-alpha","tor-0.1.2.3-alpha","tor-0.1.2.2-alpha","tor-0.1.2.1-alpha","tor-0.1.1.18-rc","tor-0.1.1.22","tor-0.1.1.21","tor-0.1.1.20","tor-0.1.1.19-rc","debian-version-0.1.1.18-rc-1","debian-version-0.1.1.22-1","debian-version-0.1.1.21-1","debian-version-0.1.1.20-1","debian-version-0.1.1.19-rc-1","debian-version-0.1.1.17-rc-1","tor-0.1.1.17-rc","debian-version-0.1.1.16-rc-1","tor-0.1.1.16-rc","tor-0.1.1.15-rc","debian-version-0.1.1.15-rc-1","debian-version-0.1.1.14-alpha-1","tor-0.1.1.14-alpha","debian-version-0.1.1.13-alpha-1","tor-0.1.1.13-alpha","debian-version-0.1.1.12-alpha-1","tor-0.1.1.12-alpha","debian-version-0.1.1.11-alpha-1","tor-0.1.1.11-alpha","debian-version-0.1.1.10-alpha-1","tor-0.1.1.10-alpha","debian-version-0.1.1.9-alpha-1","tor-0.1.1.9-alpha","debian-version-0.1.1.8-alpha-1","tor-0.1.1.8-alpha","debian-version-0.1.1.7-alpha-1","tor-0.1.1.7-alpha","debian-version-0.1.1.6-alpha-2","debian-version-0.1.1.6-alpha-1","tor-0.1.1.6-alpha","debian-version-0.1.1.5-alpha-1","tor-0.1.1.5-alpha","tor-0.1.1.4-alpha","tor-0.1.1.2-alpha","tor-0.1.1.1-alpha","tor-0.1.0.9-rc","tor-0.1.0.14","tor-0.1.0.13","tor-0.1.0.12","tor-0.1.0.11","tor-0.1.0.10","tor-0.1.0.17","tor-0.1.0.16","tor-0.1.0.15","debian-version-0.1.0.7-rc-200505171420-1","tor-0.1.0.7-rc","tor-0.1.0.6-rc","debian-version-0.1.0.9-rc-1","debian-version-0.1.0.8-rc-1","debian-version-0.1.0.14-2","debian-version-0.1.0.14-1","debian-version-0.1.0.13-1","debian-version-0.1.0.12-1","debian-version-0.1.0.11-1","debian-version-0.1.0.11-0-pre.1","debian-version-0.1.0.10-0-pre.1","tor-0.1.0.5-rc","debian-version-0.1.0.5-rc-200504272000-1","tor-0.1.0.4-rc","debian-version-0.1.0.4-rc-200504232130-1","debian-version-0.1.0.3-rc-cvs-200504231630-1","debian-version-0.1.0.3-rc-200504231430-1","debian-version-0.1.0.17-1","debian-version-0.1.0.16-1","debian-version-0.1.0.15-1","debian-version-0.1.0.3-rc-200504080730-1","debian-version-0.1.0.2-rc-cvs-200504062112-1","debian-version-0.1.0.2-rc-cvs-200504061620-1","debian-version-0.1.0.2-rc-cvs-200504031300-1","tor-0.1.0.2-rc","debian-version-0.1.0.2-rc-200504011640-1","debian-version-0.1.0.2-rc-200504011500-1","debian-version-0.1.0.1-rc-cvs-200504010815-1","debian-version-0.1.0.1-rc-cvs-200503310807-1","tor-0.1.0.1-rc","debian-version-0.0.9.9-1","debian-version-0.0.9.8-1","debian-version-0.0.9.7-1","debian-version-0.0.9.6-1","debian-version-0.0.9.5-1","debian-version-0.0.9.4-1","debian-version-0.0.9.3-1","debian-version-0.0.9.2-1","debian-version-0.0.9.10-1","tor-0.0.9.9","tor-0.0.9.7","tor-0.0.9.6","tor-0.0.9.5","tor-0.0.9.3","tor-0.0.9.2","tor-0.0.9.10","debian-version-0.0.9.1-1","tor-0.0.9.1","tor-0.0.9","debian-version-0.0.8+0.0.9rc7-1","debian-version-0.0.8+0.0.9rc6-1","tor-0.0.9rc7","tor-0.0.9rc6","debian-version-0.0.8+0.0.9rc5-1","tor-0.0.9rc5","debian-version-0.0.8+0.0.9rc3-1","tor-0.0.9rc4","tor-0.0.9rc3","debian-version-0.0.8+0.0.9rc2-1","tor-0.0.9rc2","debian-version-0.0.8+0.0.9rc1-1","tor-0.0.9rc1","debian-version-0.0.8+0.0.9pre6-1","tor-0.0.9pre6","debian-version-0.0.8+0.0.9pre5-2","tor-0.0.9pre5","debian-version-0.0.8+0.0.9pre5-1","debian-version-0.0.8+0.0.9pre4-1","tor-0.0.9pre4","debian-version-0.0.8+0.0.9pre3-1","tor-0.0.9pre3","debian-version-0.0.8+0.0.9pre2-1","tor-0.0.9pre2","debian-version-0.0.8+0.0.9pre1-1","tor-0.0.9pre1","debian-version-0.0.8-1","tor-0.0.8.1","tor-0.0.8","debian-version-0.0.7+0.0.8rc1-1","tor-0.0.8rc2","tor-0.0.8rc1","debian-version-0.0.7.2+0.0.8pre3-1","tor-0.0.8pre3","debian-version-0.0.7.2+0.0.8pre2-1","tor-0.0.8pre2","tor-0.0.8pre1","debian-version-0.0.7.1-1","debian-version-0.0.7-1","tor-0.0.7","tor-0.0.7.2","tor-0.0.7.1","tor-0.0.7rc1","debian-version-0.0.6.2-1","debian-version-0.0.6.1-1","debian-version-0.0.6-1","debian-version-0.0.5+0.0.6rc4-1","tor-0.0.6.2","tor-0.0.6.1","tor-0.0.6","debian-version-0.0.5+0.0.6rc3-1","debian-version-0.0.5+0.0.6rc2-1","tor-0.0.6incompat-merged","debian-version-0.0.5-1","tor-0.0.5","debian-version-0.0.4-1","tor-0.0.4","debian-version-0.0.3-1","tor-0.0.3","debian-version-0.0.2-1","tor-0.0.2","tor-0.0.2pre27","debian-version-0.0.1+0.0.2pre27-1","debian-version-0.0.1+0.0.2pre26-1","debian-version-0.0.1+0.0.2pre25-1","tor-0.0.2pre25","debian-version-0.0.1+0.0.2pre24-1","tor-0.0.2pre24","debian-version-0.0.1+0.0.2pre23-1","tor-0.0.2pre23","debian-version-0.0.1+0.0.2pre22-1","tor-0.0.2pre22","debian-version-0.0.1+0.0.2pre21-1","debian-version-0.0.1+0.0.2pre20-2","debian-version-0.0.1+0.0.2pre20-1","tor-0.0.2pre20","debian-version-0.0.1+0.0.2pre19-1","tor-0.0.2pre19","tor-0.0.2pre18","tor-0.0.2pre17","tor-0.0.2pre16","tor-0.0.2pre14","tor-0.0.2pre13","tor-0.0.2pre8"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-38385.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}