PT-2020-16537 · Lightning Network Daemon · Lnd
Published
2020-10-21
·
Updated
2024-01-19
·
CVE-2020-26895
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LND versions prior to 0.10.0-beta
Description
The issue allows any peer with an open channel to exploit the vulnerability, regardless of the victim's situation, such as being a routing node, payment-receiver, or payment-sender. This can lead to a loss of funds in certain situations. The vulnerability is related to the acceptance of a counterparty high-S signature and the broadcast of invalid local commitment/HTLC transactions.
Recommendations
For versions prior to 0.10.0-beta, upgrade to a version 0.11.x release as soon as possible.
At the moment, there is no information about other mitigation measures for this vulnerability.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lnd