CVEs Blog | G5 Cyber Security

CVE-2020-26895 – Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted

Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing node, payment-receiver, or payment-sender). The impact is a loss of funds in certain situations.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26895

Reference (s):

Exit mobile version