{"id":"openSUSE-SU-2022:0072-1","summary":"Security update for bitcoin","details":"This update for bitcoin fixes the following issues:\n\nUpdate to version 0.21.2\n\n* P2P protocol and network code\n  * use NetPermissions::HasFlag() in CConnman::Bind()\n  * Rate limit the processing of rumoured addresses\n* Wallet\n  * Do not iterate a directory if having an error while accessing it\n* RPC\n  * Reset scantxoutset progress before inferring descriptors\n* Build System\n  * depends: update Qt 5.9 source url\n  * Update Windows code signing certificate\n  * Use custom MacOS code signing tool\n  * Fix build with Boost 1.77.0\n* Tests and QA\n  * Build with --enable-werror by default, and document exceptions\n  * Fix intermittent feature_taproot issue\n  * Fix macOS brew install command\n  * add missing ECCVerifyHandle to base_encode_decode\n  * Run fuzzer task for the master branch only\n* GUI\n  * Do not use QClipboard::Selection on Windows and macOS.\n  * Remove user input from URI error message\n  * Draw 'eye' sign at the beginning of watch-only addresses\n* Miscellaneous\n  * Fix crash when parsing command line with -noincludeconf=0\n  * util: Properly handle -noincludeconf on command line (take 2)\n\nUpdate to version 0.21.1\n\n* Consensus:\n  * Speedy trial support for versionbits\n  * Speedy trial activation parameters for Taproot\n* P2P protocol and network code\n  * allow CSubNet of non-IP networks\n  * Avoid UBSan warning in ProcessMessage\n* Wallet\n  * Introduce DeferredSignatureChecker and have\n    SignatureExtractorClass subclass it\n  * Avoid requesting fee rates multiple times during coin selection\n* RPC and other APIs:\n  * Disallow sendtoaddress and sendmany when private keys disabled\n    CVE-2021-3195\n\nUpdate to version 0.21.0:\n\n* For full details see release-notes-0.21.0.md\n\nUpdate to version 0.20.1\n\n* Mining\n  * Fix GBT: Restore '!segwit' and 'csv' to 'rules' key\n* P2P protocol and network code\n  * Replace automatic bans with discouragement filter\n* Wallet\n  * Handle concurrent wallet loading\n  * Minimal fix to restore conflicted transaction notifications \n* RPC and other APIs\n  * Increment input value sum only once per UTXO in decodepsbt\n  * psbt: Increment input value sum only once per UTXO in decodepsbt\n  * psbt: Include and allow both non_witness_utxo and witness_utxo for segwit inputs\n* GUI\n  * Add missing QPainterPath include\n  * update Qt base translations for macOS release\n* Misc\n  * util: Don't reference errno when pthread fails\n  * Fix locking on WSL using flock instead of fcntl\n\nUpdate to version 0.20.0:\n\n* See https://github.com/bitcoin/bitcoin/blob/master/doc/release-notes/release-notes-0.20.0.md\n\n- Do not run bitcoind in daemon mode. Running it not as a\n  background process makes it working properly with journald\n  (instead of writing logs in /var/log).\n\nUpdate to version 0.19.1:\n\n* Wallet\n  * Fix origfee return for bumpfee with feerate arg\n  * Fix unique_ptr usage in boost::signals2\n  * Fix issue with conflicted mempool tx in listsinceblock\n  * Bug: IsUsedDestination shouldn't use key id as script id for\n    ScriptHash\n  * IsUsedDestination should count any known single-key address\n  * Reset reused transactions cache\n* RPC and other APIs\n  * cli: Fix fatal leveldb error when specifying\n    -blockfilterindex=basic twice\n  * require second argument only for scantxoutset start action\n  * zmq: Fix due to invalid argument and multiple notifiers\n  * psbt: handle unspendable psbts\n  * psbt: check that various indexes and amounts are within\n    bounds\n* GUI\n  * Fix missing qRegisterMetaType for size_t\n  * disable File-\u003eCreateWallet during startup\n  * Fix comparison function signature\n  * Fix unintialized WalletView::progressDialog\n* Tests and QA\n  * Appveyor improvement - text file for vcpkg package list\n  * fix 'bitcoind already running' warnings on macOS\n  * add missing #include to fix compiler errors\n* Platform support\n  * Update msvc build for Visual Studio 2019 v16.4\n  * Updates to appveyor config for VS2019 and Qt5.9.8 + msvc\n    project fixes\n  * bug-fix macos: give free bytes to F_PREALLOCATE\n* Miscellaneous\n  * init: Stop indexes on shutdown after ChainStateFlushed\n    callback\n  * util: Add missing headers to util/fees.cpp\n  * Unbreak build with Boost 1.72.0\n  * scripts: Fix symbol-check & security-check argument passing\n  * Log to net category for exceptions in ProcessMessages\n  * Update univalue subtree\n","modified":"2026-02-04T04:29:37.282977Z","published":"2022-03-03T19:01:19Z","related":["CVE-2021-3195"],"upstream":["CVE-2021-3195"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/ZQOIWU7XODRDIITDKWB45QLM5US3ATJW/"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-3195"}],"affected":[{"package":{"name":"bitcoin","ecosystem":"SUSE:Package Hub 15 SP3","purl":"pkg:rpm/suse/bitcoin&distro=SUSE%20Package%20Hub%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.21.2-bp153.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"bitcoin-test":"0.21.2-bp153.2.3.1","bitcoin-utils":"0.21.2-bp153.2.3.1","bitcoind":"0.21.2-bp153.2.3.1","libbitcoinconsensus-devel":"0.21.2-bp153.2.3.1","libbitcoinconsensus0":"0.21.2-bp153.2.3.1","bitcoin-qt5":"0.21.2-bp153.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:0072-1.json"}},{"package":{"name":"bitcoin","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/bitcoin&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.21.2-bp153.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"bitcoin-utils":"0.21.2-bp153.2.3.1","bitcoind":"0.21.2-bp153.2.3.1","libbitcoinconsensus-devel":"0.21.2-bp153.2.3.1","libbitcoinconsensus0":"0.21.2-bp153.2.3.1","bitcoin-qt5":"0.21.2-bp153.2.3.1","bitcoin-test":"0.21.2-bp153.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:0072-1.json"}}],"schema_version":"1.7.3"}