Skip to content

CVE-2025-43707 public disclosure#811

Merged
apoelstra merged 2 commits into
rust-bitcoin:masterfrom
darosior:2504_disclose_CVE-2025-43707
Apr 24, 2025
Merged

CVE-2025-43707 public disclosure#811
apoelstra merged 2 commits into
rust-bitcoin:masterfrom
darosior:2504_disclose_CVE-2025-43707

Conversation

@darosior
Copy link
Copy Markdown
Contributor

Add an entry to the CHANGELOG stating #798 was a silent fix for a crash bug which could be triggered by satisfying thresh(k,subs) fragments where k == len(subs).

Copy link
Copy Markdown
Member

@apoelstra apoelstra left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ACK 80de07a; successfully ran local tests

@apoelstra apoelstra merged commit 4a38c76 into rust-bitcoin:master Apr 24, 2025
31 checks passed
heap-coder added a commit to heap-coder/rust-miniscript that referenced this pull request Sep 27, 2025
80de07ae039d9f2f64a40c1e71ee5e9bea7679b5 CHANGELOG: disclose 12.3.1 contained a silent fix for CVE-2025-43707 (Antoine Poinsot)
6f8e37cc028a39dd06205a2f6160c114060e9b28 CHANGELOG: add entry for 12.3.0 (Antoine Poinsot)

Pull request description:

  Add an entry to the CHANGELOG stating #798 was a silent fix for a crash bug which could be triggered by satisfying `thresh(k,subs)` fragments where `k == len(subs)`.

ACKs for top commit:
  apoelstra:
    ACK 80de07ae039d9f2f64a40c1e71ee5e9bea7679b5; successfully ran local tests

Tree-SHA512: 5c5fa7b5d07295a7b8fa0cbb60ab503d14d7af689132e7d7f3f56af85c92de9336b5fe7b9f7752a40b64ec846bd9005e093af7c4b8eba6be52ff6c4527b45088
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants