en.bitcoin.it
https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures CVE-2023-33297
HIGH
bitcoin bitcoin_core Uncontrolled Resource Consumption
Record summary
CVE-2023-33297 has a selected CVSS score of 7.5 (high).
Description
Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 22, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 28, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
bitcoin_coreBrowse bitcoin / bitcoin_core | VulnCheck | Version data not supplied | |
References
Showing 12 of 13github.com
https://github.com/bitcoin/bitcoin/blob/master/doc/release-notes/release-notes-24.1.md github.com
https://github.com/bitcoin/bitcoin/issues/27586 github.com
https://github.com/bitcoin/bitcoin/issues/27623 github.com
https://github.com/bitcoin/bitcoin/pull/27610 github.com
https://github.com/dogecoin/dogecoin/issues/3243 github.com
https://github.com/visualbasic6/drain FEDORA-2023-1bae6b7751Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F2EI7SAP4QP2AJYK2JVEOO4GJ6DOBSM5 FEDORA-2023-3317c9b824Vendor advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H3CQY277NWXY3RFCZCJ4VKT2P3ROACEJ lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F2EI7SAP4QP2AJYK2JVEOO4GJ6DOBSM5 lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H3CQY277NWXY3RFCZCJ4VKT2P3ROACEJ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-33297