Vulnerability Description
Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bcoin | Bcoin | < 1.0.2 |
| Bitcoin | Bitcoin Core | >= 0.16.0, < 0.16.2 |
| Bitcoinknots | Bitcoin Knots | >= 0.16.0, < 0.16.2 |
| Btcd Project | Btcd | 0.3.0 |
| Decred | Dcrd | < 1.5.2 |
| Litecoin | Litecoin | >= 0.16.0, < 0.16.2 |
| Namecoin | Namecoin Core | >= 0.16.0, < 0.16.2 |
Related Weaknesses (CWE)
References
- https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2018-17145Vendor Advisory
- https://github.com/bitcoin/bitcoin/blob/v0.16.2/doc/release-notes.mdRelease NotesThird Party Advisory
- https://invdos.netThird Party Advisory
- https://invdos.net/paper/CVE-2018-17145.pdfExploitTechnical DescriptionThird Party Advisory
- https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2018-17145Vendor Advisory
- https://github.com/bitcoin/bitcoin/blob/v0.16.2/doc/release-notes.mdRelease NotesThird Party Advisory
- https://invdos.netThird Party Advisory
- https://invdos.net/paper/CVE-2018-17145.pdfExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2018-17145?
CVE-2018-17145 is a vulnerability with a CVSS score of 7.5 (HIGH). Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can ...
How severe is CVE-2018-17145?
CVE-2018-17145 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-17145?
Check the references section above for vendor advisories and patch information. Affected products include: Bcoin Bcoin, Bitcoin Bitcoin Core, Bitcoinknots Bitcoin Knots, Btcd Project Btcd, Decred Dcrd.