CVE-2021-31876
Summary
| CVE | CVE-2021-31876 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-13 22:15:00 UTC |
| Updated | 2021-05-26 20:12:00 UTC |
| Description | Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes it easier for attackers to trigger a loss of funds, or a denial of service attack against downstream projects such as Lightning network nodes. An unconfirmed child transaction with nSequence = 0xff_ff_ff_ff, spending an unconfirmed parent with nSequence <= 0xff_ff_ff_fd, should be replaceable because there is inherited signaling by the child transaction. However, the actual PreChecks implementation does not enforce this. Instead, mempool rejects the replacement attempt of the unconfirmed child transaction. |
Risk And Classification
Problem Types: CWE-863
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Common Vulnerabilities and Exposures - Bitcoin Wiki | MISC | en.bitcoin.it | |
| GitHub - bitcoin/bitcoin: Bitcoin Core integration/staging tree | MISC | github.com | |
| Bitcoin Optech Newsletter #148 | Bitcoin Optech | MISC | bitcoinops.org | |
| [bitcoin-dev] Full Disclosure: CVE-2021-31876 Defect in Bitcoin Core's bip125 logic | MISC | lists.linuxfoundation.org | |
| Replace-by-fee (RBF) | Bitcoin Optech | MISC | bitcoinops.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.