CVE-2018-17145
Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 4.09% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- bcoin/bcoin · bitcoin/bitcoin core · bitcoinknots/bitcoin knots · btcd project/btcd · decred/dcrd · litecoin/litecoin · namecoin/namecoin core
- Source
- cve@mitre.org
References
- https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2018-17145Vendor Advisory
- https://github.com/bitcoin/bitcoin/blob/v0.16.2/doc/release-notes.mdRelease Notes, Third Party Advisory
- https://invdos.netThird Party Advisory
- https://invdos.net/paper/CVE-2018-17145.pdfExploit, Technical Description, Third Party Advisory
- https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2018-17145Vendor Advisory
- https://github.com/bitcoin/bitcoin/blob/v0.16.2/doc/release-notes.mdRelease Notes, Third Party Advisory
- https://invdos.netThird Party Advisory
- https://invdos.net/paper/CVE-2018-17145.pdfExploit, Technical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.