CVE-2020-26896
Summary
| CVE | CVE-2020-26896 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-21 02:15:00 UTC |
| Updated | 2020-11-05 15:43:00 UTC |
| Description | Prior to 0.11.0-beta, LND (Lightning Network Daemon) had a vulnerability in its invoice database. While claiming on-chain a received HTLC output, it didn't verify that the corresponding outgoing off-chain HTLC was already settled before releasing the preimage. In the case of a hash-and-amount collision with an invoice, the preimage for an expected payment was instead released. A malicious peer could have deliberately intercepted an HTLC intended for the victim node, probed the preimage through a colluding relayed HTLC, and stolen the intercepted HTLC. The impact is a loss of funds in certain situations, and a weakening of the victim's receiver privacy. |
Risk And Classification
Problem Types: CWE-354
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| public-report-HTLC-collision.txt · GitHub | MISC | gist.github.com | Third Party Advisory |
| [Lightning-dev] CVE-2020-26896: LND Invoice Preimage Extraction | MISC | lists.linuxfoundation.org | Mailing List, Patch, Third Party Advisory |
| [Lightning-dev] Full Disclosure: CVE-2020-26896 LND "The (un)covert channel" | MISC | lists.linuxfoundation.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.