CVE-2024-34149: Medium severity Bitcoin Bitcoin Core vulnerability
In Bitcoin Core through 27.0 and Bitcoin Knots before 25.1.knots20231115, tapscript lacks a policy size limit check, a different issue than CVE-2023-50428. NOTE: some parties oppose this new limit check (for example, because they agree with the objective but disagree with the technical mechanism, or because they have a different objective).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34149?
CVE-2024-34149 is classified as a moderate severity vulnerability due to its impact on tapscript policy size limits in Bitcoin Core and Bitcoin Knots.
How do I fix CVE-2024-34149?
To fix CVE-2024-34149, upgrade to Bitcoin Core version 27.1 or later and Bitcoin Knots version 25.1.knots20231116 or later.
Who is affected by CVE-2024-34149?
CVE-2024-34149 affects users of Bitcoin Core up to version 27.0 and Bitcoin Knots prior to version 25.1.knots20231115.
What does CVE-2024-34149 affect in Bitcoin Core and Bitcoin Knots?
CVE-2024-34149 affects the tapscript implementation by lacking a policy size limit check, which could lead to undesired behavior.
Is there a recommended policy size limit for CVE-2024-34149?
Although there is no specific universally agreed policy size limit, implementing one could help mitigate risks associated with CVE-2024-34149.