CVE-2019-25220
HIGHBitcoin Core < 24.0.1 - Denial of Service via Chain Width Expansion Attack
Title source: llmDescription
Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain Width Expansion" attack) because a node does not first verify that a presented chain has enough work before committing to store it.
References (3)
Core 3
Core References
Vendor Advisory
https://bitcoincore.org/en/2024/09/18/disclose-headers-oom
Third Party Advisory
https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures
Scores
CVSS v3
7.5
EPSS
0.0078
EPSS Percentile
51.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-770
Status
published
Products (1)
bitcoin/bitcoin_core
< 24.0.1
Published
Nov 18, 2024
Tracked Since
Feb 18, 2026