CVE-2023-33297
Summary
| CVE | CVE-2023-33297 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-22 05:15:00 UTC |
| Updated | 2023-11-07 04:14:00 UTC |
| Description | Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CPU DoS on mainnet in debug mode · Issue #27586 · bitcoin/bitcoin · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 37 Update: bitcoin-core-24.1-1.fc37 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Improve performance of p2p inv to send queues by ajtowns · Pull Request #27610 · bitcoin/bitcoin · GitHub |
MISC |
github.com |
|
| remote p2p bandwidth/cpu attack · Issue #3243 · dogecoin/dogecoin · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 38 Update: bitcoin-core-24.1-1.fc38 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| One core in CPU usage rate remains at 100% for a long time, causing serious delays in new blocks and forks · Issue #27623 · bitcoin/bitcoin · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 38 Update: bitcoin-core-24.1-1.fc38 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| pad on X: "@Fidelity there is an active critical bitcoin exploit.
it is a financial attack.
observe: https://t.co/OxpktPtH49
the takeaway from pad vs bitcoin is that a botnet can remotely charge public listening node operators thousands of dollars.
that would snowball into a mass exodus of public… https://t.co/K0rhyPPDax" / X |
MISC |
x.com |
|
| en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures |
MISC |
en.bitcoin.it |
|
| [SECURITY] Fedora 37 Update: bitcoin-core-24.1-1.fc37 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| bitcoin/release-notes-24.1.md at master · bitcoin/bitcoin · GitHub |
MISC |
github.com |
|
| GitHub - visualbasic6/drain: bitdrain - remote p2p bandwidth/cpu overage attack against bitcoin, dogecoin, etc. |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 284007 Fedora Security Update for bitcoin (FEDORA-2023-3317c9b824)
- 284107 Fedora Security Update for bitcoin (FEDORA-2023-1bae6b7751)