CVE-2024-52922
MEDIUMDescription
In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes of delay when an announcing peer stalls instead of complying with the peer-to-peer protocol specification.
Is your site exposed to CVE-2024-52922?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| bitcoin | bitcoin_core |
References
Advisories & Patches
Other References
Frequently Asked Questions
What is CVE-2024-52922? +
How severe is CVE-2024-52922? +
What products are affected by CVE-2024-52922? +
How do I check if I'm vulnerable to CVE-2024-52922? +
Related Vulnerabilities
Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty …
Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offset for …
In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed …
Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.
Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum …
Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.