CVE-2024-35202: High severity bitcoin vulnerability
Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn message that are not committed to in a block's merkle root. FillBlock can be called twice for one PartiallyDownloadedBlock instance.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35202?
The severity of CVE-2024-35202 is classified as high due to its potential to cause a denial of service.
How do I fix CVE-2024-35202?
To fix CVE-2024-35202, upgrade your Bitcoin Core software to version 25.0 or later.
Who is affected by CVE-2024-35202?
CVE-2024-35202 affects all versions of Bitcoin Core prior to 25.0.
What kind of attacks does CVE-2024-35202 enable?
CVE-2024-35202 enables remote attackers to execute denial of service attacks through malicious blocktxn messages.
What should I do if I cannot upgrade to version 25.0 to mitigate CVE-2024-35202?
If upgrading is not possible, ensure that your Bitcoin node's network exposure is minimized to reduce the risk of exploitation related to CVE-2024-35202.