CVE-2024-38365 affects btcd, an alternative full node Bitcoin implementation, specifically versions 0.10 to 0.24. The vulnerability stems from an incorrect re-implementation of Bitcoin Core's "FindAndDelete()" functionality, leading to consensus critical differences. This flaw allows attackers to remotely trigger a chain split by causing btcd nodes to accept invalid blocks or reject valid ones, with a CVSS score of 8.1 (HIGH). There are no known active exploits, public exploit code, or significant community discussion surrounding this vulnerability. Users are advised to upgrade to btcd version v0.24.2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.10.0, < 0.24.2CPE matchmatch criteria | cpe:2.3:a:btcd_project:btcd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.