CVE-2018-17145: High severity bcoin vulnerability
Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-17145?
CVE-2018-17145 is a vulnerability in Bitcoin Core and Bitcoin Knots that allows remote denial of service via a flood of multiple transaction inv messages with random hashes.
Which software versions are affected by CVE-2018-17145?
Bitcoin Core versions before 0.16.2 and Bitcoin Knots versions before 0.16.2 are affected by CVE-2018-17145.
How severe is CVE-2018-17145?
CVE-2018-17145 has a severity rating of 7.5 (high).
Can other cryptocurrencies be affected by CVE-2018-17145?
Yes, other cryptocurrencies that were forked from Bitcoin Core after 2017-11-15 can also be affected by CVE-2018-17145.
How can I mitigate the CVE-2018-17145 vulnerability?
To mitigate the CVE-2018-17145 vulnerability, it is recommended to upgrade to Bitcoin Core version 0.16.2 or Bitcoin Knots version 0.16.2.