PT-2024-36556 · Unknown · Bitcoin Core
Antoine Riard
·
Published
2024-12-09
·
Updated
2025-10-23
·
CVE-2024-55563
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Bitcoin Core versions prior to 27.3
Description
The issue allows for transaction-relay jamming via an off-chain protocol attack. This can change the outcome of an HTLC (Hashed Timelock Contract) because a flood of transaction traffic prevents propagation of certain Lightning channel transactions. The vulnerability poses a threat to the Bitcoin Lightning Network, potentially disrupting transactions and leading to financial losses.
Recommendations
For Bitcoin Core versions prior to 27.3, update to version 27.3 or later to resolve the issue. As a temporary workaround, consider restricting the use of HTLCs until a patch is applied. Avoid using the
transaction-relay feature in the affected Bitcoin Core versions until the issue is resolved.Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitcoin Core