Bug 2251638 (CVE-2023-37192)

Summary: CVE-2023-37192 bitcoin-core: memory manipulation leading to transaction redirection
Product: [Other] Security Response Reporter: Avinash Hanwate <ahanwate>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
Bitcoin Core could allow a remote attacker to bypass security restrictions, caused by memory management and protection issues in the app's memory . By sending a specially crafted request, an attacker could exploit this vulnerability to redirect Bitcoin transactions to wallets of their own choosing.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2251639, 2251640    
Bug Blocks:    

Description Avinash Hanwate 2023-11-27 02:49:06 UTC
Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, potentially allowing them to redirect Bitcoin transactions to wallets of their own choosing.

Comment 1 Avinash Hanwate 2023-11-27 02:49:27 UTC
Created bitcoin-core tracking bugs for this issue:

Affects: epel-all [bug 2251640]
Affects: fedora-all [bug 2251639]