[Lightning-dev] Full Disclosure: CVE-2021-41591/ CVE-2021-41592 / CVE-2021-41593 "Dust HTLC Exposure Considered Harmful"
https://lists.linuxfoundation.org/pipermail/lightning-dev/2021-October/003257.html
The vulnerabilities are expected to be patched in:
* Eclair: v0.6.2+ (CVE-2021-41591)
* LND: v0.13.3+ (CVE-2021-41592)
* LDK: v0.0.102 (not released as production software yet)
The vulnerabilities are also affecting c-lightning (CVE-2021-41593).
--
archive: https://archive.ph/gHSdP
--
h/t @[email protected]