CVE-2024-52921
Bitcoin Core vulnerability analysis and mitigation

Overview

CVE-2024-52921 affects Bitcoin Core versions before 25.0. The vulnerability allows a peer to affect the download state of other peers by sending a mutated block. The issue was discovered in May 2023 and was fixed with the release of Bitcoin Core v25.0 (Bitcoin Core).

Technical details

The vulnerability occurs when a peer sends a mutated block (a block where the Merkle root in the header or the witness commitment in the coinbase transaction doesn't match the transactions in the block). Before version 25.0, receiving an unrequested mutated block could clear the block download state of other peers. This particularly affected compact block relay, where receiving a mutated block while waiting for a getblocktxn response would cause Bitcoin Core to forget about the compact block reconstruction state (Bitcoin Core). The vulnerability has been assigned a CVSS v3.1 Base Score of 5.3 MEDIUM (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) (NVD).

Impact

The vulnerability could hinder block propagation across the network. When a blocktxn response arrives after receiving a mutated block, it couldn't be used to reconstruct the block, potentially causing delays in block propagation throughout the network (Bitcoin Core).

Mitigation and workarounds

The vulnerability was fixed in Bitcoin Core v25.0 by ensuring that a peer can only affect its own block download state and not the download state of other peers. The fix was implemented through pull request #27608 (Bitcoin Core).

Additional resources


SourceThis report was generated using AI

Related Bitcoin Core vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-54605HIGH7.5
  • Bitcoin CoreBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesOct 28, 2025
CVE-2025-54604HIGH7.5
  • Bitcoin CoreBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesOct 28, 2025
CVE-2024-52922MEDIUM6.5
  • Bitcoin CoreBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesNov 18, 2024
CVE-2024-55563MEDIUM5.3
  • Bitcoin CoreBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoNoDec 09, 2024
CVE-2024-52921MEDIUM5.3
  • Bitcoin CoreBitcoin Core
  • cpe:2.3:a:bitcoin:bitcoin_core
NoYesNov 18, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management