Skip to content

Commit bfd5582

Browse files
authored
Merge pull request #19 from adamjonas/add-lnd-4752
add 126 (2020-12-02)
2 parents dbb4d94 + 5f5e141 commit bfd5582

File tree

1 file changed

+10
-1
lines changed

1 file changed

+10
-1
lines changed

_posts/en/newsletters/2020-12-02-newsletter.md

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -114,7 +114,12 @@ release candidates.*
114114
[Hardware Wallet Interface (HWI)][hwi repo], [Bitcoin Improvement Proposals
115115
(BIPs)][bips repo], and [Lightning BOLTs][bolts repo].*
116116

117-
- [LND #4752][] invoices: force MPP payload inclusion for non-keysend payments FIXME:adamjonas
117+
- [LND #4752][] addresses [improper preimage revelation][CVE-2020-26896] for
118+
passthrough payments described in [Newsletter #121][news121 preimage] and
119+
[#122][news122 preimage]. This change prevents the problem by forbidding the
120+
node to release the preimage without a [payment secret][payment secret],
121+
contained in a field that is not available for passthrough payments. The patch
122+
also requires the payment secret feature bit in the invoices that LND produces.
118123

119124
<!-- FIXME: harding to update topics -->
120125
{% include references.md %}
@@ -135,3 +140,7 @@ release candidates.*
135140
[news119 upfront]: /en/newsletters/2020/10/14/#ln-upfront-payments
136141
[news120 upfront]: /en/newsletters/2020/10/21/#more-ln-upfront-fees-discussion
137142
[news122 upfront]: /en/newsletters/2020/11/04/#bi-directional-upfront-fees-for-ln
143+
[CVE-2020-26896]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-26896
144+
[news121 preimage]: /en/newsletters/2020/10/28/#cve-2020-26896-improper-preimage-revelation
145+
[news122 preimage]: /en/newsletters/2020/11/04/#c-lightning-4162
146+
[payment secret]: https://github.com/lightningnetwork/lightning-rfc/commit/5776d2a7

0 commit comments

Comments
 (0)