bitcoin-dev

Public disclosure of 10 vulnerabilities affecting Bitcoin Core < 0.21.0

Public disclosure of 10 vulnerabilities affecting Bitcoin Core < 0.21.0

Original Postby Antoine Poinsot

Posted on: July 3, 2024 16:34 UTC

The project has initiated the implementation of a new vulnerability disclosure policy, which marks a significant step toward enhancing security measures.

This introduction of the policy is accompanied by the release of 10 security advisories, all of which are accessible on the project's official website. For further details, interested parties can visit https://bitcoincore.org/en/security-advisories.

In line with this advancement, there is a planned schedule for the public disclosure of vulnerabilities that have been rectified in previous versions of the software. Starting in July, the project intends to disclose vulnerabilities addressed in version 22.0. This will be followed by disclosures related to version 23.0 in August. The process will continue sequentially for each subsequent version until all vulnerabilities in old and unmaintained versions have been made public. Following this exhaustive disclosure process, the newly adopted policy will then be applied to all forthcoming versions of the project's software.

This strategic move towards transparency and proactive communication regarding security vulnerabilities underscores the project's commitment to safeguarding its user base and stakeholders. By announcing vulnerabilities in a structured manner, the project aims to foster a safer and more secure environment for its community.