CVE-2025-54604 - Disk filling from spoofed self connections

<p>Disclosure of the details of a log-filling bug which allowed an attacker to fill up the disk space of a victim node by faking self-connections. Exploitability of this bug is limited, and it would take a long time before it would cause the victim to run out of disk space. A fix was released on October 10th 2025 in Bitcoin Core v30.0.</p> <p>This issue is considered <strong>Low</strong> severity.</p> <h2 id="details">Details</h2> <p>Bitcoin Core would unconditionally log in case of self-connection. This could be exploited by an attacker by waiting for a victim to connect to it and reusing the version message nonce to establish many connections to the victim, causing it to detect those attem

Source

Bitcoin Core

A short excerpt in its original language. Read the full story at the source.

Read original source

Copyright (c) 2014 Michael Rose; 2015 Sylvain Durand; 2016 Respective Authors. MIT License. Excerpt. MIT

Comments

No registration required. Your name and comment will be public.

Name: 2–60 characters. Comment: 3–2000 characters. Plain text only. Up to one comment per minute and five per hour.

Loading comments…