CVE-2021-31876

Description from NVD

Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes it easier for attackers to trigger a loss of funds, or a denial of service attack against downstream projects such as Lightning network nodes. An unconfirmed child transaction with nSequence = 0xff_ff_ff_ff, spending an unconfirmed parent with nSequence <= 0xff_ff_ff_fd, should be replaceable because there is inherited signaling by the child transaction. However, the actual PreChecks implementation does not enforce this. Instead, mempool rejects the replacement attempt of the unconfirmed child transaction.

Information Acquisition Date:2021-05-31T12:40Z
CVSS 2.0: 6.4 MEDIUM CVSS 3.x: 6.5 MEDIUM

▼ CVSS3 Vec CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

▼ CVSS2 Vec AV:N/AC:L/Au:N/C:N/I:P/A:P

NVD References

 https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2021-31876
     source:MISC
     tags:Third Party Advisory    
 https://bitcoinops.org/en/newsletters/2021/05/12/
     source:MISC
     tags:Vendor Advisory    
 https://bitcoinops.org/en/topics/replace-by-fee/
     source:MISC
     tags:Vendor Advisory    
 https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2021-May/018893.html
     source:MISC
     tags:Mailing List    Third Party Advisory    
 https://github.com/bitcoin/bitcoin
     source:MISC
     tags:Third Party Advisory    

Refer to Information on External Sites

CVE InfomationExploits or more Infomation
mitreEXPLOIT DATABASE
NVD0day.today
vulmon.comgithub
CVE DetailsTwitter
JVN ENG JPN
Reconshell

Software Tag:



List of frequently cited URLs

URLNum of Times Referred to
https://bitcoinmagazine.com/technical/bitcoin-core-cve-2021...12
https://twitter.com/BitcoinMagazine/status/13958512042075217943

Information from Twitter

User URL Info Source Date
No Data

List of frequently cited URLs

URLNum of Times Referred to
bitcoinmagazine.com12
twitter.com3

Information from Twitter

User URL Info Source
No Data

GitHub Search Results: Up to 10
NameURL
No Data

GitHub Search Results: Up to 10
NameURL
No Data

2022/10/11 Score : 0
Added Har-sia Database : 2021/05/07
Last Modified : 2022/10/11
Highest Scored Date : 2021/05/22
Highest Score : 39