#1121333 tor: Please update the Tor version, as 0.4.8.16 is deemed "not recommended" by the tor network

Package:
tor
Source:
tor
Description:
anonymizing overlay network for TCP
Submitter:
Gunnar Wolf
Date:
2026-01-09 09:25:01 UTC
Severity:
normal
Tags:
#1121333#5
Date:
2025-11-24 15:02:57 UTC
From:
To:
Hi,

Tor relays running Debian are being reported as “running a version of Tor
that is too old and may be missing important security fixes”, and marked as
“Not recommended” by the Tor network. i.e.:

https://metrics.torproject.org/rs.html#details/0B8851E9615E67C3BED365590BC91BDA63542CAD

The version currently provided in Debian is 0.4.8.16-1 (and was last
updated in late March!), while the latest non-alpha available is 0.4.8.21.

Please provide updated packages!

Thanks,

    – Gunnar.

#1121333#10
Date:
2025-11-24 15:14:40 UTC
From:
To:
Also, upon restarting the service, I get the following in my system logs:

Tor[85862]: Please upgrade! This version of Tor (0.4.8.16) is obsolete, according to the directory authorities. Recommended versions are: 0.4.8.21,0.4.9.3-alpha

#1121333#15
Date:
2025-11-27 10:59:36 UTC
From:
To:
Current version of tor stable is 0.4.8.21

Both unstable and stable are stuck at version 0.4.8.16

#1121333#22
Date:
2026-01-08 23:41:48 UTC
From:
To:
0.4.8.21 seems to have landed in trixie-backports (and forky), but
bookworm-backports is still stuck on old 0.4.8.14-1~bpo12+1

So it is time to upgrade those oldstable tor routers...

#1121333#27
Date:
2026-01-09 09:23:20 UTC
From:
To:
It's in oldstable-backports-sloppy (as it's not coming from the next
release as far as bookworm is concerned).