CVE-2023-33297
HIGH EXPLOITED IN THE WILDBitcoin Core < 24.1 - Denial of Service via Inventory Queue Drain Inefficiency
Title source: llmExploitation Summary
CVE-2023-33297 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).
Description
Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.
References (10)
Core 10
Core References
Release Notes
https://github.com/bitcoin/bitcoin/blob/master/doc/release-notes/release-notes-24.1.md
Issue Tracking
https://github.com/bitcoin/bitcoin/issues/27586
Issue Tracking
https://github.com/bitcoin/bitcoin/issues/27623
Issue Tracking, Patch
https://github.com/bitcoin/bitcoin/pull/27610
Various Sources
https://x.com/123456/status/1711601593399828530
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2EI7SAP4QP2AJYK2JVEOO4GJ6DOBSM5/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H3CQY277NWXY3RFCZCJ4VKT2P3ROACEJ/
Scores
CVSS v3
7.5
EPSS
0.0140
EPSS Percentile
69.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
VulnCheck KEV
2023-05-22
InTheWild.io
2023-05-22
CWE
CWE-400
Status
published
Products (1)
bitcoin/bitcoin_core
< 24.1
Published
May 22, 2023
Tracked Since
Feb 18, 2026