CVE-2024-52920

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Nov 18, 2024
CWE ID 770

Summary

CVE-2024-52920 is a newly disclosed vulnerability in Bitcoin Core versions prior to 0.20.0. This issue permits remote attackers to trigger an infinite loop, leading to a denial of service (DoS) condition. The vulnerability is triggered through the handling of malformed GETDATA messages. Bitcoin Core users are advised to upgrade to version 0.20.0 or later to mitigate this risk. The infinite loop consumes significant system resources, causing the Bitcoin node to become unresponsive and effectively preventing it from processing transactions, making it important for users to apply the patch promptly to avoid potential DoS attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share