Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump btcd to v0.23.4 #17

Merged
merged 1 commit into from
Apr 11, 2023
Merged

Bump btcd to v0.23.4 #17

merged 1 commit into from
Apr 11, 2023

Conversation

drklee3
Copy link
Member

@drklee3 drklee3 commented Apr 10, 2023

Cherry-pick of 95c4c15

Fixes vulnerability:

GO-2022-1098
Erroneous message decoding can cause denial of service. Improper
checking of maximum witness size during node message decoding
prevented nodes in Lightning Labs lnd (before 0.15.2-beta) to
sync.
More info: https://pkg.go.dev/vuln/GO-2022-1098
Found in: github.com/btcsuite/btcd@v0.22.1
Fixed in: github.com/btcsuite/btcd@v0.23.2

@drklee3 drklee3 merged commit a1c73fd into kava-release-v0.21.x Apr 11, 2023
@drklee3 drklee3 deleted the dl-bump-btcd branch April 11, 2023 17:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant