<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/tails-7-9-1-xsflkpujs" -->

---
title: Tails 7.9.1 | daily.dev
description: Tails 7.9.1 is a security-focused release that updates Tor Browser to 15.0.17, the Tor client to 0.4.9.11, and the Linux kernel to 6.12.94. The kernel update...
canonical: https://daily.dev/posts/tails-7-9-1-xsflkpujs
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Tails 7.9.1 | daily.dev
og:description: Tails 7.9.1 is a security-focused release that updates Tor Browser to 15.0.17, the Tor client to 0.4.9.11, and the Linux kernel to 6.12.94. The kernel update...
og:url: https://daily.dev/posts/tails-7-9-1-xsflkpujs
og:image: https://api.daily.dev/og/posts/XsfLkPUjS.png
og:image:alt: Tails 7.9.1
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Tails 7.9.1

**[Tails](https://daily.dev/sources/tails)** · 2 min read · 2 upvotes · 0 comments

## Summary

Tails 7.9.1 is a security-focused release that updates Tor Browser to 15.0.17, the Tor client to 0.4.9.11, and the Linux kernel to 6.12.94. The kernel update patches two CVEs — CVE-2026-43503 (DirtyClone) and CVE-2026-46331 (PACKET_EDIT_MEME) — both privilege escalation vulnerabilities that could allow a malicious application to gain admin rights and potentially deanonymize users. The threat is considered unlikely but plausible for well-resourced attackers such as governments or hacking firms. Automatic upgrades are available from Tails 7.0 or later.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://tails.net/news/version_7.9.1>

## Questions this post answers

### What does Tails 7.9.1 fix?

Tails 7.9.1 updates Tor Browser to 15.0.17, the Tor client to 0.4.9.11, and the Linux kernel to 6.12.94. The kernel update fixes CVE-2026-43503 (DirtyClone) and CVE-2026-46331 (PACKET_EDIT_MEME), two vulnerabilities that could let a malicious application in Tails gain administrative privileges and potentially deanonymize the user if chained with another exploit.

_Anyone running Tails should track releases like this on daily.dev to stay ahead of privilege-escalation risks._

### Can I automatically upgrade to Tails 7.9.1?

Yes, automatic upgrades to Tails 7.9.1 are available from Tails 7.0 or later. If an automatic upgrade fails or Tails does not start afterward, a manual upgrade is the recommended fallback; installing fresh on a new USB stick instead of upgrading will erase the Persistent Storage.

_Following upgrade guidance like this on daily.dev helps avoid losing persistent data during a Tails update._

### How severe is CVE-2026-46331 in Tails?

CVE-2026-46331, nicknamed PACKET_EDIT_MEME, allows an application already running in Tails to gain administration privileges, which could then be combined with another exploit to take full control of the system and deanonymize the user. The exploit is considered unlikely and would require a strong attacker such as a government or hacking firm; no in-the-wild exploitation is known.

_Security-conscious developers can follow deanonymization-risk disclosures like this via daily.dev._

## Similar posts on daily.dev

- [Tails 7.7.3](https://daily.dev/posts/tails-7-7-3-sfrtjuaqd) · Tails · 1 upvotes · 0 comments
- [Tails 7.8.1](https://daily.dev/posts/tails-7-8-1-oknmvxr9s) · Tails · 0 upvotes · 0 comments
- [Tails 7.10.1](https://daily.dev/posts/tails-7-10-1-qyqplraql) · Tails · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#linux](https://daily.dev/tags/linux)

[View this post on daily.dev](https://daily.dev/posts/tails-7-9-1-xsflkpujs)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Tails 7.9.1","url":"https://daily.dev/posts/tails-7-9-1-xsflkpujs","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/tails-7-9-1-xsflkpujs"},"datePublished":"2026-07-01T11:37:36.761Z","dateModified":"2026-09-13T20:27:09.175Z","description":"Tails 7.9.1 is a security-focused release that updates Tor Browser to 15.0.17, the Tor client to 0.4.9.11, and the Linux kernel to 6.12.94. The kernel update...","image":"https://media.daily.dev/image/upload/s--P4t4XyoV--/f_auto/v1722860399/public/Placeholder%2001","thumbnailUrl":"https://media.daily.dev/image/upload/s--P4t4XyoV--/f_auto/v1722860399/public/Placeholder%2001","isAccessibleForFree":true,"articleSection":"Tails","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Tails","logo":"https://media.daily.dev/image/upload/s--CcfkcLeI--/f_auto/v1747894944/logos/tails","url":"https://daily.dev/sources/tails"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/tails-7-9-1-xsflkpujs","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,linux","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Tails","item":"https://daily.dev/sources/tails"},{"@type":"ListItem","position":3,"name":"Tails 7.9.1"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/tails-7-9-1-xsflkpujs#faq","mainEntity":[{"@type":"Question","name":"What does Tails 7.9.1 fix?","acceptedAnswer":{"@type":"Answer","text":"Tails 7.9.1 updates Tor Browser to 15.0.17, the Tor client to 0.4.9.11, and the Linux kernel to 6.12.94. The kernel update fixes CVE-2026-43503 (DirtyClone) and CVE-2026-46331 (PACKET_EDIT_MEME), two vulnerabilities that could let a malicious application in Tails gain administrative privileges and potentially deanonymize the user if chained with another exploit. Anyone running Tails should track releases like this on daily.dev to stay ahead of privilege-escalation risks."}},{"@type":"Question","name":"Can I automatically upgrade to Tails 7.9.1?","acceptedAnswer":{"@type":"Answer","text":"Yes, automatic upgrades to Tails 7.9.1 are available from Tails 7.0 or later. If an automatic upgrade fails or Tails does not start afterward, a manual upgrade is the recommended fallback; installing fresh on a new USB stick instead of upgrading will erase the Persistent Storage. Following upgrade guidance like this on daily.dev helps avoid losing persistent data during a Tails update."}},{"@type":"Question","name":"How severe is CVE-2026-46331 in Tails?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-46331, nicknamed PACKET_EDIT_MEME, allows an application already running in Tails to gain administration privileges, which could then be combined with another exploit to take full control of the system and deanonymize the user. The exploit is considered unlikely and would require a strong attacker such as a government or hacking firm; no in-the-wild exploitation is known. Security-conscious developers can follow deanonymization-risk disclosures like this via daily.dev."}}]}
```

