CVE-2023-33297

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
22/05/2023
Last modified:
28/01/2025

Description

Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is inefficient, as exploited in the wild in May 2023.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:* 24.1 (excluding)