CVE-2012-2459General(bitcoin / bitcoin_core)

LOWCVSS 5.0 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch bitcoin bitcoin_core systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Unspecified vulnerability in bitcoind and Bitcoin-Qt before 0.4.6, 0.5.x before 0.5.5, 0.6.0.x before 0.6.0.7, and 0.6.x before 0.6.2 allows remote attackers to cause a denial of service (block-processing outage and incorrect block count) via unknown behavior on a Bitcoin network.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bitcoin_core

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 4 classified signals
  • Disclosure: 1 classified signal
  • Peaked 5d ago at 1 mentions (2026-07-11); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
bitcoin_core

10 versions affected across 1 product

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-07-11: 1Mentions · 2026-07-31: 1Mentions · 2026-08-06: 1Mentions · 2026-08-13: 1Mentions · 2026-08-22: 1Mentions · 2026-10-06: 1Patch / Workaround · 2026-07-31: 1Technical Details · 2026-07-31: 107-1107-3108-0608-1308-2210-06
Signal classification2 categories
General
480.0%
Disclosure
120.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-07-111
General1
2026-07-311
Disclosure1
2026-08-061
General1
2026-08-131
General1
2026-08-221
General1
Full discourse6 posts
  • Bitcoin Butlers@bitcoinbutlers
    General

    @JWWeatherman_ @SeedSigner CVE-2010-5139, CVE-2018-17144, CVE-2013-3220, CVE-2012-2459, CVE-2011-4447 and you only said no to part of the issue raised - single point of failure, OP also references merely one potential part of a quorum.

    Post summary

    The tweet merely lists several CVE identifiers without providing any technical details, exploits, or mitigation information.

    00160223
    764 followersView on X
  • rbitcoin@rbitcoin_org

    Post-0.7.0 fix sweep on master: • fee estimates for a 2-block target no longer quote the pricier 1-block rate • blocks mutated with a duplicated tx pair (the old CVE-2012-2459 trick) are rejected and the peer dropped • a crash mid mempool save no longer causes a restart loop

    0003081
    187 followersView on X
  • 代码训练师@TrainCodeMan
    Disclosure

    至今 Bitcoin Core(比特币 C++ 官方底层客户端)公开记录在案的 CVE 安全漏洞总数在 60 个左右。 按照严重程度和对整个比特币网络的影响,这些漏洞大致可以分为以下三个层级: 1. 致命/灾难级漏洞(共 3 次) 这 3 次漏洞直接威胁到了比特币的账本绝对正确性(如增发货币、双花)或导致整个网络发生非预期的硬分叉: 2010 年 8 月:整数溢出漏洞(CVE-2010-5139) 影响: 攻击者构造了一笔特殊交易,绕过了 C++ 的数值范围检查,凭空凭空刷出了 1,840 亿枚 BTC。  解决: 中本聪与核心开发者在 5 小时内发布修复补丁,并通过硬分叉抹去了这笔异常交易。 2013 年 3 月:数据库版本不兼容导致链分裂(Berkeley DB 限制) 影响: 0.8 版本节点(使用 LevelDB)接受了一个巨大的区块,但 0.7 及更早版本节点(使用 Berkeley DB)因为锁限制拒绝了该区块,导致比特币网络分裂成两条链。  解决: 开发者紧急呼吁矿工切回 0.7 版本,强制作废了新链,成功归一。 2018 年 9 月:重复输入校验漏洞(CVE-2018-17144) 影响: 在重构代码以提高性能时,开发者误删了一段检查交易中是否存在“重复输入”的代码。攻击者可以借此进行**双花攻击(重复花费同一笔比特币)**或导致全网节点崩溃。  解决: 被安全专家提前隐密发现并通报,团队迅速发布 0.16.3 版本静默修复,未被攻击者实际利用。  2. 高/中危漏洞(约 25–30 次) 这类漏洞通常无法篡改账本或盗取比特币,但会导致节点远程崩溃、内存耗尽(OOM)、网络延迟或攻击 SPV 轻钱包: 远程崩溃与内存暴涨(DoS): 如 CVE-2015-3641(恶意节点投递超大 P2P 消息导致 4GB+ 内存占用崩溃)、CVE-2018-17145(INV 消息泛滥)、CVE-2024-52911(脚本解释器远程崩溃)。  网络隔离/分裂隐患: 如 CVE-2012-2459(Merkle 树变异区块缓存拒绝攻击)、CVE-2024-52912(节点时间偏移计算中的溢出缺陷导致网络分裂)。 3. 低危/第三方依赖库漏洞(约 20–30 次) 依赖库缺陷: Bitcoin Core 早期集成的第三方库(如用于自动映射端口的 ⁠miniupnpc⁠,CVE-2015-6031)出现的缓冲区溢出或内存泄漏。 本地 RPC / GUI 缺陷: 仅影响本地钱包管理或开启了特定 Debug 选项的节点,攻击者需要本地权限或诱导用户点击特定链接(如 CVE-2024-52918,通过超长 URL 导致 Bitcoin-Qt 崩溃)。

    Post summary

    The article outlines the history of Bitcoin Core CVEs, describing severity tiers, technical details, and patch actions, without referencing PoC availability or active exploitation.

    20000141
    35 followersView on X
  • riddik@nvee3
    General

    Can we prove Bitcoin’s rules? Optech 414: Keagan McClelland’s btc-verified (Lean4) applies formal verification to the Bitcoin protocol — math-backed checks that code matches a spec. Early focus includes Merkle roots + the CVE-2012-2459 class issue. Consensus bugs are existential. Clearer specs help. https://bitcoinops.org/en/newsletters/2026/07/17/ #Bitcoin #BitcoinCore

    Post summary

    The post references a formal‑verification tool for Bitcoin that targets Merkle root validation and a historical CVE‑2012‑2459 class issue, but provides no exploit, patch, or detailed technical information.

    0001032
    323 followersView on X
  • riddik@nvee3
    General

    Can code be proven correct? Formal verification = math-backed “does this match the spec?” Tests sample. Proofs aim at whole classes of behavior. Bitcoin angle: consensus bugs are existential. Optech 414 covers early Lean4 work (Merkle roots / CVE-2012-2459 class). https://bitcoinops.org/en/newsletters/2026/07/17/ #Bitcoin #BitcoinEducation

    Post summary

    The text references a CVE class in a general discussion about formal verification and Bitcoin consensus bugs, but offers no specific evidence of exploits, patches, or technical details.

    0000035
    318 followersView on X
  • LX@LXunchained
    General

    So the Bitcoin side nets out to: no vulnerabilities, strong defensive posture, with the review confirming intact protections for the historically-famous bugs (value-overflow CVE-2010-5139, the CVE-2018-17144 duplicate-input inflation bug, CVE-2012-2459 merkle mutation, the 2024 receive-buffer OOM fix).

    Post summary

    The review indicates Bitcoin remains secure, with all historically‑known CVEs still adequately protected; no new vulnerabilities or exploitation details are present.

    00000131
    2.9K followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
Appbitcoinbitcoin_core---
Appbitcoinbitcoin_core0.3.10--
Appbitcoinbitcoin_core0.3.11--
Appbitcoinbitcoin_core0.3.12--
Appbitcoinbitcoin_core0.3.4--
Appbitcoinbitcoin_core0.3.5--
Appbitcoinbitcoin_core0.3.8--
Appbitcoinbitcoin_core0.4.0--
Appbitcoinbitcoin_core0.4.1--
Appbitcoinbitcoin_core0.4.1--
Appbitcoinbitcoin_core0.4.4--
Appbitcoinbitcoin_core0.4.4--
Appbitcoinbitcoin_core0.5.0--

Explore more