AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 20 Bitcoin

Merge bitcoin/bitcoin#35873: test: add a tx_valid vector for CVE-2024-38365

Public commit record

What the developer wrote

Authored by merge-script

100/100 · Strong
Merge bitcoin/bitcoin#35873: test: add a tx_valid vector for CVE-2024-38365

6cd2fa5fb4b6d25b8400d2a7683ceb78610c0b4f test: add a tx_valid vector for CVE-2024-38365 (JP)

Pull request description:

Suggested by darosior in #35835.

`FindAndDelete` only matches whole pushes at opcode boundaries, so a push that carries the signature inside its data is left in the scriptCode. btcd (<0.24.2) removed any push containing the signature, computed a different sighash, and would have rejected a transaction Core accepts: the chain split in [CVE-2024-38365](https://delvingbitcoin.org/t/cve-2024-38365-public-disclosure-btcd-findanddelete-bug/1184).

The rule is already covered from the failure side, in `script_FindAndDelete` and in the `tx_invalid.json` vectors where the signature sits under a non-standard pushdata prefix. What was missing is the positive direction: a transaction Core must accept because nothing is deleted.

This adds one vector to `tx_valid.json`, with `OP_CHECKSIGVERIFY <0xaaaa||sig>` as the P2SH redeemScript and the minimal 8-byte DER signature (r = s = 1). The pubkey is recovered from that signature and the sighash Core computes, so it verifies only if the `<0xaaaa||sig>` push survives into the scriptCode. `CONST_SCRIPTCODE` doesn't fire — `FindAndDelete` finds nothing — and the vector runs with every flag.

To check it actually discriminates, I patched `EvalChecksigPreTapscript` to drop any push whose data contains the signature, the way btcd did. The vector fails with that patch and passes without it.

Tested with:

```
build/bin/test_bitcoin --run_test=transaction_tests
```

ACKs for top commit:
fametrano:
ACK 6cd2fa5fb4b6d25b8400d2a7683ceb78610c0b4f
sedited:
ACK 6cd2fa5fb4b6d25b8400d2a7683ceb78610c0b4f

Tree-SHA512: a08412e00ed43570c3cf556da1d243a40b9684ce17eb6d3017267c3e5e82f9cde232e077944b0ec9476df70e767caf0fcd33be5473dfd53ed2241f7b24a33b1d
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit only adds a new test case to Bitcoin Core's transaction validation test data. The test confirms that Bitcoin Core correctly handles a specific signature-checking quirk that caused a bug in another Bitcoin implementation (btcd). It does not change any production code, so it cannot by itself introduce a vulnerability or fix one in Bitcoin Core. It is a regression-style test for a known, already-disclosed issue (CVE-2024-38365).

Recommended action

No action required. Review the test vector for correctness if auditing test coverage, but this commit is not a security patch and does not require deployment urgency.

Security signals we found

01

References CVE-2024-38365 in commit title and test comments

02

Adds a positive tx_valid test vector for FindAndDelete behavior

03

No changes to consensus, script, or P2P code

04

Test-only change with no runtime behavior change

Risk score

Why this scored 20/100

Our methodology →
Potential impact 2/30
Exploitability 1/25
Stealth signal 1/15
Affected reach 2/15
Confidence 9/10
Evidence quality 5/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.