All errata/sisyphus/ALT-PU-2023-1884-2
ALT-PU-2023-1884-2

Package update bitcoin in branch sisyphus

Version25.0-alt1
Published2026-02-04
Max severityHIGH
Severity:

Closed issues (3)

CVE-2023-33297
HIGH7.5

Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.

Published: 2023-05-22Modified: 2025-01-28
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2024-35202
HIGH7.5

Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn message that are not committed to in a block's merkle root. FillBlock can be called twice for one PartiallyDownloadedBlock instance.

Published: 2024-10-10Modified: 2025-05-22
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H