-
Notifications
You must be signed in to change notification settings - Fork 122
Open
Description
We recently investigated the Bitcoin issues which are related to privacy protection, vulnerability patches, or security enhancements. We have also checked the repoName source code. Results show that these issues and their PRs are not backported yet. Henceforth, we suggest that repoName should backport the PRs listed below for the considerations of software security and integrity.
- Bitcoin PR#17906, avoid uninitialized reads.
- Bitcoin PR#16572, fix a
Charvariable used asBool. - Bitcoin PR#15039, avoid leaking
nLockTimefingerprint. - Bitcoin PR#14993, fix data race in
InterruptRPC(). - Bitcoin PR#13808, shuffle coins before grouping, for privacy protection.
- Bitcoin PR#13683, avoid potential null pointer dereference.
Some of these issues and PRs are not severe security-related, but backports can avoid the chaos ecosystem of Bitcoin-forked projects and the potential vulnerabilities in the future.
Reported by de957ad9679f28a38f02f00cc7928bce8fb424882ff060a3c09c32895b1474cc.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels