PT-2023-24276 · Unknown+1 · Bitcoin Core+1

·

CVE-2023-33297

·

Published

2023-05-22

·

Updated

2024-11-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Bitcoin Core versions prior to 24.1
Description The issue allows attackers to cause a denial of service, specifically CPU consumption, because draining the inventory-to-send queue is inefficient. This has been exploited in the wild in May 2023.
Recommendations For Bitcoin Core versions prior to 24.1, update to version 24.1 or later to resolve the issue. As a temporary workaround, consider enabling debug mode to mitigate the risk of CPU consumption attacks. Restrict access to the inventory-to-send queue to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1884
ALT-PU-2024-15200
CVE-2023-33297

Affected Products

Alt Linux
Bitcoin Core