# Stable release 0.4.8.21

**URL:** https://forum.torproject.org/t/stable-release-0-4-8-21/20817
**Category:** Tor Release Announcement
**Tags:** tor
**Created:** [November 18, 2025, 8:16pm UTC](https://forum.torproject.org/t/stable-release-0-4-8-21/20817 "2025-11-18T20:16:45Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![dgoulet](https://forum.torproject.org/user_avatar/forum.torproject.org/dgoulet/32/18_2.png) [@dgoulet](https://forum.torproject.org/u/dgoulet)
#### Post date: [November 18, 2025, 8:16pm UTC](https://forum.torproject.org/t/stable-release-0-4-8-21/20817/1 "2025-11-18T20:16:45Z")

</div>

# Where to Download

- [Tarballs](https://dist.torproject.org/)
- [Gitlab Repository](https://gitlab.torproject.org/tpo/core/tor)
- [Bug Report](https://gitlab.torproject.org/tpo/core/tor/-/issues/new)

# Changes

Below are the major changes of the released versions and links to more detailed release notes.

## Stable

Similar to version **0.4.8.20** , we released **0.4.8.21** yesterday due to additional issues discovered in relation to the fixes included in the previous stable release. This update addresses another [medium-severity](https://gitlab.torproject.org/tpo/core/team/-/wikis/NetworkTeam/SecurityPolicy) **remote crash** and memory DoS vulnerabilities affecting the Conflux subsystem.

As of around 23:00 UTC yesterday, our Debian packages were made public, and at the time of writing approximately 40% of Exit relays have upgraded—what we consider a sufficient threshold to proceed with this announcement.

As always, please upgrade as soon as possible.

Thank you!

#### Release Notes

- [0.4.8.x](https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.8/ReleaseNotes)

---

<div class="post-metadata">

### Author: ![atari](https://forum.torproject.org/user_avatar/forum.torproject.org/atari/32/392_2.png) [@atari](https://forum.torproject.org/u/atari)
#### Post date: [November 20, 2025, 9:12am UTC](https://forum.torproject.org/t/stable-release-0-4-8-21/20817/2 "2025-11-20T09:12:27Z")

</div>

> [@Stable release 0.4.8.20](https://forum.torproject.org/t/stable-release-0-4-8-20/20781/7):
>
> will there be 0.4.8.20 packages in the official Debian-trixie-repo anytime soon? [Debian – Details of package tor in trixie](https://packages.debian.org/trixie/tor)

will there be ~~0.4.8.20~~ 0.4.8.21 packages in the official Debian-trixie-repo anytime soon? [Debian -- Details of package tor in trixie](https://packages.debian.org/trixie/tor)

or are we waiting for 0.4.8.2x?

> it is done when it is finished…

---

<div class="post-metadata">

### Author: ![atari](https://forum.torproject.org/user_avatar/forum.torproject.org/atari/32/392_2.png) [@atari](https://forum.torproject.org/u/atari)
#### Post date: [November 20, 2025, 9:12am UTC](https://forum.torproject.org/t/stable-release-0-4-8-21/20817/3 "2025-11-20T09:12:31Z")

</div>

[Tor Project | Download Tor](https://www.torproject.org/download/tor/) still hands out 0.4.8. **20** instead of **0.4.8.21**

---

<div class="post-metadata">

### Author: ![atari](https://forum.torproject.org/user_avatar/forum.torproject.org/atari/32/392_2.png) [@atari](https://forum.torproject.org/u/atari)
#### Post date: [December 26, 2025, 9:42am UTC](https://forum.torproject.org/t/stable-release-0-4-8-21/20817/4 "2025-12-26T09:42:14Z")

</div>

For Debian Trixie it is possible to upgrade your tor manually by installing a package from Debian sid: [Debian -- Details of package tor in sid](https://packages.debian.org/sid/tor) (choose your correct architecture)

For amd64:

```auto
wget https://ftp.debian.org/debian/pool/main/t/tor/tor_0.4.8.21-1_amd64.deb
sudo dpkg -i tor_0.4.8.21-1_amd64.deb

```

---

<div class="post-metadata">

### Author: ![yurikoles](https://forum.torproject.org/user_avatar/forum.torproject.org/yurikoles/32/6533_2.png) [@yurikoles](https://forum.torproject.org/u/yurikoles)
#### Post date: [January 16, 2026, 2:55am UTC](https://forum.torproject.org/t/stable-release-0-4-8-21/20817/5 "2026-01-16T02:55:34Z")

</div>

> The Tor Project maintains its own [Debian package repository](https://deb.torproject.org).

> **[Installation](https://support.torproject.org/little-t-tor/getting-started/installing/#debian-ubuntu)**
>
> These instructions are meant for installing tor the network daemon i.e. little-t tor. For instructions to install Tor Browser, refer to the Tor Browser user manual.

---

<div class="post-metadata">

### Author: ![atari](https://forum.torproject.org/user_avatar/forum.torproject.org/atari/32/392_2.png) [@atari](https://forum.torproject.org/u/atari)
#### Post date: [January 31, 2026, 4:31am UTC](https://forum.torproject.org/t/stable-release-0-4-8-21/20817/6 "2026-01-31T04:31:34Z")

</div>

Also _trixie-backports_ are working since beginning of this year. [[Instructions](https://backports.debian.org/Instructions/)]

[https://metadata.ftp-master.debian.org/changelogs//main/t/tor/tor\_0.4.8.21-1~bpo13+2\_changelog](https://metadata.ftp-master.debian.org/changelogs//main/t/tor/tor_0.4.8.21-1~bpo13+2_changelog)

Thank you @weasel & @lavamind ❤
