File tree Expand file tree Collapse file tree 1 file changed +10
-1
lines changed
Expand file tree Collapse file tree 1 file changed +10
-1
lines changed Original file line number Diff line number Diff line change @@ -114,7 +114,12 @@ release candidates.*
114114[ Hardware Wallet Interface (HWI)] [ hwi repo ] , [ Bitcoin Improvement Proposals
115115(BIPs)] [ bips repo ] , and [ Lightning BOLTs] [ bolts repo ] .*
116116
117- - [ LND #4752 ] [ ] invoices: force MPP payload inclusion for non-keysend payments FIXME: adamjonas
117+ - [ LND #4752 ] [ ] addresses [ improper preimage revelation] [ CVE-2020-26896 ] for
118+ passthrough payments described in [ Newsletter #121 ] [ news121 preimage ] and
119+ [ #122 ] [ news122 preimage ] . This change prevents the problem by forbidding the
120+ node to release the preimage without a [ payment secret] [ payment secret ] ,
121+ contained in a field that is not available for passthrough payments. The patch
122+ also requires the payment secret feature bit in the invoices that LND produces.
118123
119124<!-- FIXME: harding to update topics -->
120125{% include references.md %}
@@ -135,3 +140,7 @@ release candidates.*
135140[ news119 upfront ] : /en/newsletters/2020/10/14/#ln-upfront-payments
136141[ news120 upfront ] : /en/newsletters/2020/10/21/#more-ln-upfront-fees-discussion
137142[ news122 upfront ] : /en/newsletters/2020/11/04/#bi-directional-upfront-fees-for-ln
143+ [ CVE-2020-26896 ] : https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26896
144+ [ news121 preimage ] : /en/newsletters/2020/10/28/#cve-2020-26896-improper-preimage-revelation
145+ [ news122 preimage ] : /en/newsletters/2020/11/04/#c-lightning-4162
146+ [ payment secret ] : https://github.com/lightningnetwork/lightning-rfc/commit/5776d2a7
You can’t perform that action at this time.
0 commit comments