Explore top 10 tips to secure your open-source projects now. Read More
×An update that solves 6 vulnerabilities and has 6 bug fixes can now be installed.. openSUSE security update: security update for bitcoin ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21149-1 Rating: important References: * bsc#1125092 * bsc#1149711 * bsc#1181784 * bsc#1181786 * bsc#1217678 * bsc#1231507 Cross-References: * CVE-2018-20587 * CVE-2019-15947 * CVE-2020-14198 * CVE-2021-3195 * CVE-2023-37192 * CVE-2024-35202 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 6 vulnerabilities and has 6 bug fixes can now be installed. Description: This update for bitcoin fixes the following issues: Changes in bitcoin: - Reference the tracking bugs for CVEs already fixed in current bitcoin (the affected versions all predate the shipped release): * CVE-2018-20587 (boo#1125092) * CVE-2019-15947 (boo#1149711) * CVE-2020-14198 (boo#1181786) * CVE-2021-3195 (boo#1181784) * CVE-2023-37192 (boo#1217678) * CVE-2024-35202 (boo#1231507) Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-344=1 Package List: - openSUSE Leap 16.0: bitcoin-qt5-27.1-bp160.2.1 bitcoin-test-27.1-bp160.2.1 bitcoin-utils-27.1-bp160.2.1 bitcoind-27.1-bp160.2.1 libbitcoinconsensus-devel-27.1-bp160.2.1 libbitcoinconsensus0-27.1-bp160.2.1 References: * https://www.suse.com/security/cve/CVE-2018-20587.html * https://www.suse.com/security/cve/CVE-2019-15947.html * https://www.suse.com/security/cve/CVE-2020-14198.html * https://www.suse.com/security/cve/CVE-2021-3195.html * https://www.suse.com/security/cve/CVE-2023-37192.html * https://www.suse.com/security/cve/CVE-2024-35202.html . An important updatefor openSUSE fixing multiple bitcoin security issues and bugs, ensuring system integrity and performance.. openSUSE bitcoin security patch important fixes. . Severity: Important. LinuxSecurity.com Team
A vulnerability has been discovered in Bitcoin, which can lead to a denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202408-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Bitcoin: Denial of Service Date: August 07, 2024 Bugs: #908084 ID: 202408-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Bitcoin, which can lead to a denial of service. Background ========== Bitcoin Core consists of both "full-node" software for fully validating the blockchain as well as a bitcoin wallet. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ net-p2p/bitcoind < 25.0 > = 25.0 Description =========== Please review the CVE identifier referenced below for details. Impact ====== Bitcoin Core, when debug mode is not used, allows attackers to cause a denial of service (CPU consumption) because draining the inventory-to- send queue is inefficient, as exploited in the wild in May 2023. Workaround ========== There is no known workaround at this time. Resolution ========== All Bitcoin users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-p2p/bitcoind-25.0" References ========== [ 1 ] CVE-2023-33297 https://nvd.nist.gov/vuln/detail/CVE-2023-33297 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202408-12 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any securityconcerns should be addressed to
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for bitcoin ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0052-1 Rating: moderate References: Cross-References: CVE-2018-17144 CVSS scores: CVE-2018-17144 (NVD) : 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2018-17144 (SUSE): 7.4 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for bitcoin fixes the following issues: Update to version 26.0, including the following changes: - Enable LTO and test package for Leap - Enable sqlite3 support for wallet - Enable asm optimizations unconditionally Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-52=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 ppc64le s390x x86_64): bitcoin-qt5-26.0-bp155.2.3.1 bitcoin-test-26.0-bp155.2.3.1 bitcoin-utils-26.0-bp155.2.3.1 bitcoind-26.0-bp155.2.3.1 libbitcoinconsensus-devel-26.0-bp155.2.3.1 libbitcoinconsensus0-26.0-bp155.2.3.1 References: https://www.suse.com/security/cve/CVE-2018-17144.html . openSUSE System Update for ethereum addresses security flaws of moderate risk, enhancing platform reliability and functionality.. openSUSE Security, Bitcoin Update, Patch Installation. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for bitcoin ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:0072-1 Rating: moderate References: Cross-References: CVE-2021-3195 CVSS scores: CVE-2021-3195 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for bitcoin fixes the following issues: Update to version 0.21.2 * P2P protocol and network code * use NetPermissions::HasFlag() in CConnman::Bind() * Rate limit the processing of rumoured addresses * Wallet * Do not iterate a directory if having an error while accessing it * RPC * Reset scantxoutset progress before inferring descriptors * Build System * depends: update Qt 5.9 source url * Update Windows code signing certificate * Use custom MacOS code signing tool * Fix build with Boost 1.77.0 * Tests and QA * Build with --enable-werror by default, and document exceptions * Fix intermittent feature_taproot issue * Fix macOS brew install command * add missing ECCVerifyHandle to base_encode_decode * Run fuzzer task for the master branch only * GUI * Do not use QClipboard::Selection on Windows and macOS. * Remove user input from URI error message * Draw "eye" sign at the beginning of watch-only addresses * Miscellaneous * Fix crash when parsing command line with -noincludeconf=0 * util: Properly handle -noincludeconf on command line (take 2) Update to version 0.21.1 * Consensus: * Speedy trial support for versionbits * Speedy trial activation parameters for Taproot * P2P protocol and network code * allow CSubNet ofnon-IP networks * Avoid UBSan warning in ProcessMessage * Wallet * Introduce DeferredSignatureChecker and have SignatureExtractorClass subclass it * Avoid requesting fee rates multiple times during coin selection * RPC and other APIs: * Disallow sendtoaddress and sendmany when private keys disabled CVE-2021-3195 Update to version 0.21.0: * For full details see release-notes-0.21.0.md Update to version 0.20.1 * Mining * Fix GBT: Restore "!segwit" and "csv" to "rules" key * P2P protocol and network code * Replace automatic bans with discouragement filter * Wallet * Handle concurrent wallet loading * Minimal fix to restore conflicted transaction notifications * RPC and other APIs * Increment input value sum only once per UTXO in decodepsbt * psbt: Increment input value sum only once per UTXO in decodepsbt * psbt: Include and allow both non_witness_utxo and witness_utxo for segwit inputs * GUI * Add missing QPainterPath include * update Qt base translations for macOS release * Misc * util: Don't reference errno when pthread fails * Fix locking on WSL using flock instead of fcntl Update to version 0.20.0: * See tes-0.20.0.md - Do not run bitcoind in daemon mode. Running it not as a background process makes it working properly with journald (instead of writing logs in /var/log). Update to version 0.19.1: * Wallet * Fix origfee return for bumpfee with feerate arg * Fix unique_ptr usage in boost::signals2 * Fix issue with conflicted mempool tx in listsinceblock * Bug: IsUsedDestination shouldn't use key id as script id for ScriptHash * IsUsedDestination should count any known single-key address * Reset reused transactions cache * RPC and other APIs * cli: Fix fatal leveldb error when specifying -blockfilterindex=basic twice * require second argument only for scantxoutset start action * zmq: Fix dueto invalid argument and multiple notifiers * psbt: handle unspendable psbts * psbt: check that various indexes and amounts are within bounds * GUI * Fix missing qRegisterMetaType for size_t * disable File-> CreateWallet during startup * Fix comparison function signature * Fix unintialized WalletView::progressDialog * Tests and QA * Appveyor improvement - text file for vcpkg package list * fix "bitcoind already running" warnings on macOS * add missing #include to fix compiler errors * Platform support * Update msvc build for Visual Studio 2019 v16.4 * Updates to appveyor config for VS2019 and Qt5.9.8 + msvc project fixes * bug-fix macos: give free bytes to F_PREALLOCATE * Miscellaneous * init: Stop indexes on shutdown after ChainStateFlushed callback * util: Add missing headers to util/fees.cpp * Unbreak build with Boost 1.72.0 * scripts: Fix symbol-check & security-check argument passing * Log to net category for exceptions in ProcessMessages * Update univalue subtree Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-72=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 ppc64le s390x x86_64): bitcoin-qt5-0.21.2-bp153.2.3.1 bitcoin-test-0.21.2-bp153.2.3.1 bitcoin-utils-0.21.2-bp153.2.3.1 bitcoind-0.21.2-bp153.2.3.1 libbitcoinconsensus-devel-0.21.2-bp153.2.3.1 libbitcoinconsensus0-0.21.2-bp153.2.3.1 References: https://www.suse.com/security/cve/CVE-2021-3195.html . OpenSUSE has released a security patch for CVE-2021-3195 impacting bitcoin addresses; follow the steps provided to secure your system effectively. openSUSE Update, Bitcoin Security Fix, CVE-2021-3195. . LinuxSecurity.com Team
Multiple vulnerabilities have been discovered in Bitcoin. In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it may dump a core file. If a user were to mishandle a core file, an attacker can reconstruct the user's . MGASA-2020-0458 - Updated bitcoin packages fix security vulnerabilities Publication date: 17 Dec 2020 URL: https://advisories.mageia.org/MGASA-2020-0458.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-15947, CVE-2020-14198 Multiple vulnerabilities have been discovered in Bitcoin. In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it may dump a core file. If a user were to mishandle a core file, an attacker can reconstruct the user's wallet.dat file, including their private keys, via a grep "6231 0500" command (CVE-2019-15947). Bitcoin Core 0.20.0 allows remote denial of service (CVE-2020-14198). References: - https://bugs.mageia.org/show_bug.cgi?id=27731 - https://security.gentoo.org/glsa/202009-18 - https://www.cve.org/CVERecord?id=CVE-2019-15947 - https://www.cve.org/CVERecord?id=CVE-2020-14198 SRPMS: - 7/core/bitcoin-0.20.1-1.mga7 . Mageia has issued new bitcoin packages addressing security issues such as unencrypted wallet information and potential denial-of-service risks.. Bitcoin Security,Mageia 7,Memory Exploit,Denial of Service. . Severity: Important. LinuxSecurity.com Team
Remote denial of service (application crash) exploitable by miners via duplicate input (CVE-2018-17144). References: - https://bugs.mageia.org/show_bug.cgi?id=23681 . MGASA-2018-0415 - Updated bitcoin packages fix security vulnerability Publication date: 26 Oct 2018 URL: https://advisories.mageia.org/MGASA-2018-0415.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-17144 Remote denial of service (application crash) exploitable by miners via duplicate input (CVE-2018-17144). References: - https://bugs.mageia.org/show_bug.cgi?id=23681 - - https://www.cve.org/CVERecord?id=CVE-2018-17144 SRPMS: - 6/core/bitcoin-0.16.3-1.mga6 . MGASA-2018-0415 - Updated bitcoin packages fix security vulnerability Publication date: 26 Oct 2018 . remote, denial, service, (application, crash), exploitable, miners, duplicate, input, (cve-2018-171. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for bitcoin ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:3001-1 Rating: important References: #1108992 Cross-References: CVE-2018-17144 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for bitcoin to version 0.16.3 fixes the following issues: - CVE-2018-17144: Prevent remote denial of service (application crash) exploitable by miners via duplicate input (bsc#1108992). For additional changes please check the changelog. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-1098=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1098=1 - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2018-1098=1 Package List: - openSUSE Leap 42.3 (x86_64): bitcoin-debugsource-0.16.3-7.3.1 bitcoin-qt5-0.16.3-7.3.1 bitcoin-qt5-debuginfo-0.16.3-7.3.1 bitcoin-test-0.16.3-7.3.1 bitcoin-test-debuginfo-0.16.3-7.3.1 bitcoin-utils-0.16.3-7.3.1 bitcoin-utils-debuginfo-0.16.3-7.3.1 bitcoind-0.16.3-7.3.1 bitcoind-debuginfo-0.16.3-7.3.1 libbitcoinconsensus-devel-0.16.3-7.3.1 libbitcoinconsensus0-0.16.3-7.3.1 libbitcoinconsensus0-debuginfo-0.16.3-7.3.1 - openSUSE Leap 15.0 (x86_64): bitcoin-debuginfo-0.16.3-lp150.2.3.1 bitcoin-debugsource-0.16.3-lp150.2.3.1 bitcoin-qt5-0.16.3-lp150.2.3.1 bitcoin-qt5-debuginfo-0.16.3-lp150.2.3.1 bitcoin-test-0.16.3-lp150.2.3.1 bitcoin-test-debuginfo-0.16.3-lp150.2.3.1 bitcoin-utils-0.16.3-lp150.2.3.1 bitcoin-utils-debuginfo-0.16.3-lp150.2.3.1 bitcoind-0.16.3-lp150.2.3.1 bitcoind-debuginfo-0.16.3-lp150.2.3.1 libbitcoinconsensus-devel-0.16.3-lp150.2.3.1 libbitcoinconsensus0-0.16.3-lp150.2.3.1 libbitcoinconsensus0-debuginfo-0.16.3-lp150.2.3.1 - openSUSE Backports SLE-15 (aarch64 ppc64le s390x x86_64): bitcoin-qt5-0.16.3-bp150.3.3.1 bitcoin-test-0.16.3-bp150.3.3.1 bitcoin-utils-0.16.3-bp150.3.3.1 bitcoind-0.16.3-bp150.3.3.1 libbitcoinconsensus-devel-0.16.3-bp150.3.3.1 libbitcoinconsensus0-0.16.3-bp150.3.3.1 References: https://www.suse.com/security/cve/CVE-2018-17144.html https://bugzilla.suse.com/1108992 -- . A crucial enhancement for bitcoin on Fedora addresses remote vulnerabilities, bolstering overall system resilience and safeguarding integrity.. openSUSE Bitcoin Update, Remote Exploit Prevention, Denial of Service Fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.