Datacarrier size limits bypassed through obfuscation
CVE-2023-50428

5.3MEDIUM

Key Information:

Vendor

Bitcoin

Vendor
CVE Published:
9 December 2023

Badges

đź“° News Worthy

What is CVE-2023-50428?

The CVE-2023-50428 vulnerability has been identified in Bitcoin Core and Bitcoin Knots, allowing the bypassing of datacarrier size limits by obfuscating data as code. It has been actively exploited by the Inscriptions group, affecting network performance and increasing transaction fees. This vulnerability is particularly concerning due to its potential impact on the Bitcoin network's stability and efficiency. Developer Luke Dashjr has been working towards addressing the vulnerability, and while a fix has been implemented in Bitcoin Knots v25.1, Bitcoin Core remains vulnerable. The implications of a future fix continue to be controversial, as it may lead to the end of the Ordinals Protocol, impacting the booming industry related to BRC20 tokens. The urgency of the situation is highlighted by the assignment of the CVE-2023-50428 identifier, with the evolving situation generating intense interest and dividing the crypto community.

News Articles

Bitcoin Core on Alert: Ordinals Vulnerability, an Officially Declared Threat!

Controversy surrounding Bitcoin's saturation due to Ordinals: the flaw, now identified as CVE-2023-50428, marks a turning point.

Bitcoin Core Vulnerability Exposes Risks in Datacarrier Limits: NVD Flags Security Concerns

NVD has discovered a critical vulnerability (CVE-2023-50428) in Bitcoin Core, which allows datacarrier limit bypass and poses significant network risks, notably exploited by Ordinals.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • đź“°

    First article discovered by Bicatalyst

  • Vulnerability published

  • Vulnerability Reserved

.