en.bitcoin.it
https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures CVE-2023-50428
MEDIUM
Bitcoin Core and Bitcoin Knots Datacarrier Size Limit Bypass Vulnerability
Record summary
CVE-2023-50428 has a selected CVSS score of 5.3 (medium).
Description
In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, datacarrier size limits can be bypassed by obfuscating data as code (e.g., with OP_FALSE OP_IF), as exploited in the wild by Inscriptions in 2022 and 2023. NOTE: although this is a vulnerability from the perspective of the Bitcoin Knots project, some others consider it "not a bug."
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Dec 5, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
bitcoin_coreBrowse bitcoin / bitcoin_core | VulnCheck | Version data not supplied | |
References
7github.com
https://github.com/bitcoin/bitcoin/blob/65c05db660b2ca1d0076b0d8573a6760b3228068/src/kernel/mempool_options.h github.com
https://github.com/bitcoin/bitcoin/pull/28408 github.com
https://github.com/bitcoin/bitcoin/tags github.com
https://github.com/bitcoinknots/bitcoin/blob/aed49ce8989334c364a219a6eb016a3897d4e3d7/doc/release-notes.md nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-50428 twitter.com
https://twitter.com/LukeDashjr/status/1732204937466032285