CVE-2025-54604 - Disk filling from spoofed self connections
<p>Disclosure of the details of a log-filling bug which allowed an attacker to fill up the disk space of a victim node by faking self-connections. Exploitability of this bug is limited, and it would take a long time before it would cause the victim to run out of disk space. A fix was released on October 10th 2025 in Bitcoin Core v30.0.</p> <p>This issue is considered <strong>Low</strong> severity.</p> <h2 id="details">Details</h2> <p>Bitcoin Core would unconditionally log in case of self-connection. This could be exploited by an attacker by waiting for a victim to connect to it and reusing the version message nonce to establish many connections to the victim, causing it to detect those attem
Bitcoin Core
A short excerpt in its original language. Read the full story at the source.
Read original sourceCopyright (c) 2014 Michael Rose; 2015 Sylvain Durand; 2016 Respective Authors. MIT License. Excerpt. MIT
Comments
No registration required. Your name and comment will be public.
Loading comments…