bitcoin-dev

Public disclosure of 2 vulnerabilities affecting Bitcoin Core < v22.0

Public disclosure of 2 vulnerabilities affecting Bitcoin Core < v22.0

Original Postby Niklas Goegge

Posted on: July 31, 2024 17:01 UTC

Bitcoin Core has identified bugs that are present in all versions prior to v22.0.

As part of its efforts to enhance security measures, the project has been working towards adopting a new vulnerability disclosure policy. Detailed information about this policy, as well as two security advisories, is available on the Bitcoin Core website, accessible through their security advisories page. In line with this new policy, Bitcoin Core plans to incrementally reveal vulnerabilities that have been addressed in successive versions. Initially, disclosures concerning fixes implemented in version v23.0 will be made public later in August. This will be followed by disclosures related to version v24.0 in September, with subsequent announcements planned for older, unmaintained versions until all known vulnerabilities have been disclosed. This systematic approach signifies Bitcoin Core's commitment to transparency and security, marking a significant step forward in how the project handles vulnerability disclosures for both existing and future versions.