CVE-2022-39389 describes a block parsing bug in Lightning Network Daemon (lnd) versions prior to v0.15.4, affecting lnd and btcd implementations. This vulnerability can lead to a degraded node state where channel opening and on-chain transaction detection are impaired. The potential impact includes loss of funds if a CSV expiry is reached during a breach or a CLTV delta expires. Rated with a CVSS score of 6.5 (MEDIUM), this vulnerability has a network attack vector and low attack complexity, requiring no user interaction. While it primarily impacts integrity and availability (I:L/A:L), the risk of fund loss is significant. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.23.3CPE matchmatch criteria | cpe:2.3:a:btcd_project:btcd:*:*:*:*:*:*:*:* | ||
< 0.15.4CPE matchmatch criteria | cpe:2.3:a:lightning_network_daemon_project:lightning_network_daemon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.