Security Advisory

CVE-2020-26895

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-10-21 02:00:23
Last updated 2024-08-04 16:03:22
Assigner mitre
State PUBLISHED

Description

Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing node, payment-receiver, or payment-sender). The impact is a loss of funds in certain situations.