CVE-2022-44797: Critical severity Lightning Network Daemon Project Lightning Network Daemon vulnerability
btcd before 0.23.2, as used in Lightning Labs lnd before 0.15.2-beta and other Bitcoin-related products, mishandles witness size checking.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/btcsuite/btcdto a version that resolves this vulnerability.Fixed in 0.23.2 - Upgrade
Upgrade
go/github.com/lightningnetwork/lndto a version that resolves this vulnerability.Fixed in 0.15.2-beta
Event History
Frequently Asked Questions
What is the severity of CVE-2022-44797?
CVE-2022-44797 is considered a medium severity vulnerability due to its impact on witness size checking in btcd and related products.
How do I fix CVE-2022-44797?
To mitigate CVE-2022-44797, upgrade btcd to version 0.23.2 or lnd to version 0.15.2-beta.
Which versions of btcd are affected by CVE-2022-44797?
All versions of btcd prior to 0.23.2 are affected by CVE-2022-44797.
Which versions of lnd are affected by CVE-2022-44797?
All versions of lnd prior to 0.15.2-beta are affected by CVE-2022-44797.
What does CVE-2022-44797 affect specifically?
CVE-2022-44797 affects the handling of witness size checking in btcd and Lightning Labs' lnd.