The software that lets users independently verify Bitcoin payments is getting an update aimed at speeding up those checks and fixing security flaws, with a release targeted for October.
Bitcoin Core 32.0 entered release-candidate testing on Monday, according to the project’s schedule. Developers are aiming for October 10 to deliver the finished version, though testing could change that timeline.
Myriad: Where does Bitcoin go next? Click to make your prediction.
Bitcoin Core lets computers verify Bitcoin transactions and blocks. The update mainly affects node operators and developers who use the software to run wallets and other services.
According to the draft release notes, the update can speed up block checks by reading database information in parallel, without changing how quickly Bitcoin produces blocks. Four wallet commands will also default to a newer format for exchanging partially signed transactions between wallets and signing devices, though applications can still request the older version.
A security fix prevents crafted wallet names from triggering commands on a node’s computer. The flaw affected non-Windows systems where an authenticated user could create wallets and the walletnotify feature was configured to run commands when wallet transactions occurred.
A separate patch addresses excessive memory use in the new HTTP server, which handles requests from connected applications.
Contributor Matthew Zipkin, posting as pinheadmz, described a “memory exhaustion scenario” in his patch proposal. His initial assessment limited the risk to authenticated clients.
Zipkin said he found the flaw while auditing Bitcoin Core’s new HTTP server with Kimi K3, an AI model also used by the Bitcoin Red Team to search for vulnerabilities in Bitcoin software. An earlier fix had addressed part of the problem, he explained, but a way to exhaust the computer’s available memory—an “OOM,” or out-of-memory, condition—remained.
During review of that same patch, GitHub user jeanpablojp found that requests without credentials could also cause memory growth when the REST interface was enabled. After Zipkin revised the patch, the reviewer reported that 16 unauthenticated connections caused about 3 MB of memory growth over 90 seconds, compared with 3.2 GB before.
The patch was merged September 5 for Bitcoin Core 32.0 as part of ongoing work to improve the software’s security.
Other Bitcoin software developers have addressed separate vulnerabilities in recent weeks. Hardware-wallet maker BitBox patched two severe firmware flaws in August, reporting no evidence of exploitation. Developers of the payments software Core Lightning also warned node operators about confirmed vulnerabilities while preparing fixes.
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。