Bugzilla – Bug 1211673
VUL-0: CVE-2023-33297: bitcoin: Denial-of-service
Last modified: 2023-05-24 09:15:03 UTC
CVE-2023-33297 Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-33297 https://bugzilla.redhat.com/show_bug.cgi?id=2209426 https://www.cve.org/CVERecord?id=CVE-2023-33297 http://www.cvedetails.com/cve/CVE-2023-33297/ https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures https://github.com/bitcoin/bitcoin/blob/master/doc/release-notes/release-notes-24.1.md https://github.com/bitcoin/bitcoin/issues/27586 https://github.com/bitcoin/bitcoin/issues/27623 https://github.com/bitcoin/bitcoin/pull/27610
Affected: - openSUSE:Backports:SLE-15-SP4/bitcoin 0.21.2 - openSUSE:Factory/bitcoin 24.0.1