Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain Width Expansion" attack) because a node does not first verify that a presented chain has enough work before committing to store it.
References
| Link | Resource |
|---|---|
| https://bitcoincore.org/en/2024/09/18/disclose-headers-oom | Vendor Advisory |
| https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures | Third Party Advisory |
| https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2019-October/017354.html | Mailing List |
Configurations
History
17 Jun 2026, 02:31
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (es) Bitcoin Core anterior a la versión 24.0.1 permite a atacantes remotos causar una denegación de servicio (caída del demonio) mediante una inundación de cadenas de cabeceras de baja dificultad (también conocido como un ataque de 'expansión del ancho de cadena') porque un nodo no verifica primero que una cadena presentada tenga suficiente trabajo antes de comprometerse a almacenarla. |
22 May 2025, 16:56
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://bitcoincore.org/en/2024/09/18/disclose-headers-oom - Vendor Advisory | |
| References | () https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures - Third Party Advisory | |
| References | () https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2019-October/017354.html - Mailing List | |
| First Time |
Bitcoin bitcoin Core
Bitcoin |
|
| CPE | cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:* |
18 Nov 2024, 17:35
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| CWE | CWE-770 |
18 Nov 2024, 17:11
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
18 Nov 2024, 04:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-11-18 04:15
Updated : 2026-06-17 02:31
NVD link : CVE-2019-25220
Mitre link : CVE-2019-25220
CVE.ORG link : CVE-2019-25220
JSON object : View
Products Affected
bitcoin
- bitcoin_core
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
