Eenentwintig Nieuwsfeed's avatar
Eenentwintig Nieuwsfeed
npub10en2...0kj9
Bitcoin Nieuws dat ertoe doet. https://t.me/Eenentwintig https://t.me/Eenentwintignieuws
Disclosure of CVE-2024-35202 Before Bitcoin Core v25.0, an attacker could remotely crash Bitcoin Core nodes by triggering an assertion in the blocktxn message handling logic. This issue is considered High severity. Details When receiving a block announcement via a cmpctblock message, Bitcoin Core attempts to reconstruct the announced block using the transactions in its own mempool as well as other available transactions. If reconstruction fails due to missing transactions it will request them from the announcing peer via a getblocktxn message. In response a blocktxn message is expected, which should contain the requested transactions. The compact block protocol employs shortened transaction identifiers to reduce bandwidth. These short-ids are 6 byte in size, resulting in a small chance for collisions (i.e. transaction A has the same short-id as transaction B) upon block reconstruction. Collisions will be detected as the merkle root computed from the reconstructed set of transactions will not match the merkle root from the block announcement. Peers should not be punished for collisions as they may happen spuriously, therefore they are handled by falling back to requesting the full block. Bitcoin Core will create an instance of PartiallyDownloadedBlock whenever a new compact block is received. If missing transactions are requested, the instance is persisted until the corresponding blocktxn message is processed. Upon receiving the blocktxn message, PartiallyDownloadedBlock::FillBlock is called, attempting to reconstruct the full block. In the collision case described above, the full block is requested but the PartiallyDownloadedBlock instance as well as the other state related to the underlying block request is left untouched. This leaves room for a second blocktxn message for the same block to be processed and trigger FillBlock to be called again. This violates the assumption (documented as an assert statement) that FillBlock can only be called once and causes the node to crash. An attacker does not need to get lucky by triggering a collision, as the collision handling logic can easily be triggered by simply including transactions in the blocktxn message that are not committed to in the block’s merkle root. Attribution Credit goes to Niklas Gögge for discovering and disclosing the vulnerability, as well as fixing the issue in Timeline 2022-10-05 - Niklas Gögge reports the issue to the Bitcoin Core security mailing list. 2023-01-24 - PR #26898 containing the fix is merged. 2023-05-25 - Bitcoin Core 25.0 is released with the fix. 2024-10-09 - Public disclosure. #Eenentwintig #Nieuws #News #BitcoinNews
UN Cybercrime Draft Convention Approved Unanimously Despite Widespread Opposition The United Nations approved its first cybercrime treaty—a massive surveillance pact that mandates intrusive domestic surveillance measures and states’ cooperation in surveillance and data sharing—in a unanimous vote last week. #Eenentwintig #Nieuws #News #BitcoinNews
Seedless Keys And DLCs: How Lava Is Making Bitcoin Custody Easy Shezan Maredia, founder and CEO of Lava, is working to create an easy-to-use and secure Bitcoin financial app. Lava Vault, a state-of-the-art self-custody wallet, is its newest feature, while Lava Loans is on the way. #Eenentwintig #Nieuws #News #BitcoinNews
Craig Wright Referred to UK Prosecutors for Consideration of Perjury and Forgery Charges Today, a verdict was handed down against Craig Wright in the COPA vs CSW trial. Judge Mellor ruled that Wright’s behavior warrants a referral to the Crown Prosecution Service (CPS) for a possible criminal investigation on charges of perjury. #Eenentwintig #Nieuws #News #BitcoinNews
Mt. Gox Repayment Program Set To Begin 2024 has been the year of liquidation. First, the German government decided to offload the 50,000 coins it seized from Movies 2k. During those 27 days, the market took a 25% dip, hitting a low of $ 54,000, while buyers tried to absorb this influx of coins. After the German government emptied its coffers, the […] The post Mt. Gox Repayment Program Set To Begin appeared first on The Bitcoin Manual. #Eenentwintig #Nieuws #News #BitcoinNews
Bitcoin 2024 to Host 'Bitcoin Propaganda Track' In $5,000 Winner Take All Challenge Contestants will showcase their talents by creating original Bitcoin commercials, memes, and more, to win the grand prize of $5,000 in BTC. #Eenentwintig #Nieuws #News #BitcoinNews