https://github.com/bitcoin/bitcoin/pull/14249/files
checkTransaction is defined in verify.cpp:
https://github.com/bitcoin/bitcoin/blob/master/src/consensus...
The last argument, fCheckDuplicateInputs, causes inputs to be checked for duplicates. A comment inside this method notes:
// Check for duplicate inputs - note that this check is slow so we skip it in CheckBlock
To summarize, the fix appears to replace the faster call to checkTransaction in CheckBlock with the slower version that checks for duplicate inputs in each transaction of a new block. What's not clear to me yet is how failure to check for duplicate inputs in a block's transactions leads to DoS.
Many consider Bitcoin Core to define the Bitcoin protocol. If this is true, then the new release can be considered a soft fork update.
Previously, blocks containing transactions with duplicate inputs would have been considered valid. Now, such a block will be rejected by patched nodes.
This case is an excellent example of how difficult it is to determine what exactly the Bitcoin protocol actually requires.
We only gradually "discover" the protocol by exhaustively following every branch of the Bitcoin Core code base.