CVE-2025-54605 - Disk filling from invalid blocks

<p>Disclosure of the details of a log-filling bug which allowed an attacker to cause a victim node to fill up its disk space by repeatedly sending invalid blocks. Exploitability of this bug is limited, as it would take a long time before it would cause the victim to run out of disk space. A fix was released on October 10th 2025 in Bitcoin Core v30.0.</p> <p>This issue is considered <strong>Low</strong> severity.</p> <h2 id="details">Details</h2> <p>A node would unconditionally log when receiving a block that fails basic sanity checks, or when receiving a block that branches off prior to the last checkpoint. By repeatedly sending such an invalid block to a victim node, an attacker could cause

Source

Bitcoin Core

A short excerpt in its original language. Read the full story at the source.

Read original source

Copyright (c) 2014 Michael Rose; 2015 Sylvain Durand; 2016 Respective Authors. MIT License. Excerpt. MIT

Comments

No registration required. Your name and comment will be public.

Name: 2–60 characters. Comment: 3–2000 characters. Plain text only. Up to one comment per minute and five per hour.

Loading comments…