btcd before 0.23.2, as used in Lightning Labs lnd before 0.15.2-beta and other Bitcoin-related products, mishandles witness size checking.
References
Link | Resource |
---|---|
https://github.com/btcsuite/btcd/pull/1896 | Patch Third Party Advisory |
https://github.com/lightningnetwork/lnd/issues/7002 | Exploit Issue Tracking Third Party Advisory |
https://github.com/btcsuite/btcd/releases/tag/v0.23.2 | Release Notes Third Party Advisory |
https://github.com/lightningnetwork/lnd/releases/tag/v0.15.2-beta | Release Notes Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2022-11-06 20:15
Updated : 2022-11-14 10:25
NVD link : CVE-2022-44797
Mitre link : CVE-2022-44797
JSON object : View
CWE
Products Affected
lightning_network_daemon_project
- lightning_network_daemon
btcd_project
- btcd