CVE-2024-52919
Bitcoin Core vulnerability analysis and mitigation

Overview

CVE-2024-52919 affects Bitcoin Core versions before 22.0. The vulnerability involves a CAddrMan nIdCount integer overflow that can result in an assertion failure and daemon exit when exploited through a flood of addr messages (Bitcoin Core). The vulnerability was discovered by Eugene Siegel and was fixed in September 2021 with the release of Bitcoin Core version 22.0 (Bitcoin Core).

Technical details

The vulnerability stems from a 32-bit nIdCount field in CAddrMan that is incremented on every insertion into addrman. When this counter reaches 2^32 entries through addr message flooding, the identifier overflows, triggering an assertion failure that crashes the daemon. The vulnerability has been assigned a CVSS base score of 6.5 MEDIUM (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) by CISA-ADP (NVD).

Impact

When successfully exploited, the vulnerability causes the Bitcoin Core daemon to crash through an assertion failure, effectively creating a denial of service condition. This can disrupt the normal operation of Bitcoin nodes running vulnerable versions of the software (Bitcoin Core).

Mitigation and workarounds

The vulnerability was fixed in Bitcoin Core version 22.0, released on September 13, 2021. Users running affected versions should upgrade to Bitcoin Core 22.0 or later to mitigate this vulnerability (Bitcoin Core).

Additional resources


SourceThis report was generated using AI

Related Bitcoin Core vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-54605HIGH7.5
  • Bitcoin CoreBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesOct 28, 2025
CVE-2025-54604HIGH7.5
  • Bitcoin CoreBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesOct 28, 2025
CVE-2024-52922MEDIUM6.5
  • Bitcoin CoreBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesNov 18, 2024
CVE-2024-55563MEDIUM5.3
  • Bitcoin CoreBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoNoDec 09, 2024
CVE-2024-52921MEDIUM5.3
  • Bitcoin CoreBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesNov 18, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management