PT-2023-24276 · Unknown+1 · Bitcoin Core+1
Kev
·
Published
2023-05-22
·
Updated
2024-11-14
·
CVE-2023-33297
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Bitcoin Core versions prior to 24.1
Description
The issue allows attackers to cause a denial of service, specifically CPU consumption, because draining the inventory-to-send queue is inefficient. This has been exploited in the wild in May 2023.
Recommendations
For Bitcoin Core versions prior to 24.1, update to version 24.1 or later to resolve the issue. As a temporary workaround, consider enabling debug mode to mitigate the risk of CPU consumption attacks. Restrict access to the inventory-to-send queue to minimize the risk of exploitation.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Bitcoin Core