   for an annoying SOCKS-parsing bug that affected users in earlier 0.3.5.x
+  It also includes a fix for a medium-severity security bug affecting Tor
+ and later. All Tor instances running an affected release
+  should upgrade to,,, or
+  o Major bugfixes (cell scheduler, KIST, security):
+    - Make KIST consider the outbuf length when computing what it can
+      put in the outbuf. Previously, KIST acted as though the outbuf
+      were empty, which could lead to the outbuf becoming too full. It
+      is possible that an attacker could exploit this bug to cause a Tor
+      client or relay to run out of memory and crash. Fixes bug 29168;
+      bugfix on This issue is also being tracked as
+      TROVE-2019-001 and CVE-2019-8955.
   o Major bugfixes (networking, backport from
     - Gracefully handle empty username/password fields in SOCKS5
       username/password auth messsage and allow SOCKS5 handshake to

