High severity7.5NVD Advisory· Published Oct 10, 2024· Updated Jun 17, 2026
CVE-2024-35202
CVE-2024-35202
Description
Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn message that are not committed to in a block's merkle root. FillBlock can be called twice for one PartiallyDownloadedBlock instance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:*range: <25.0
- (no CPE)range: <25.0
- Bitcoin Core/Bitcoin Coredescription
- osv-coords2 versionspkg:rpm/opensuse/bitcoin&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/bitcoin&distro=openSUSE%20Tumbleweed
< 27.1-bp160.2.1+ 1 more
- (no CPE)range: < 27.1-bp160.2.1
- (no CPE)range: < 31.0-2.1
Patches
Vulnerability mechanics
References
5- bitcoincore.org/en/2024/10/08/disclose-blocktxn-crash/nvdPatchVendor Advisory
- en.bitcoin.it/wiki/Common_Vulnerabilities_and_ExposuresnvdThird Party Advisory
- github.com/bitcoin/bitcoin/blob/master/doc/release-notes/release-notes-25.0.mdnvdRelease Notes
- github.com/bitcoin/bitcoin/pull/26898nvdIssue Tracking
- github.com/bitcoin/bitcoin/releases/tag/v25.0nvdRelease Notes
News mentions
0No linked articles in our index yet.