FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

bitcoin: don't read past a truncated Elements block header by Andezion · Pull Request #9594 · ElementsProject/lightning · GitHub

Repository navigation

bitcoin: don't read past a truncated Elements block header - #9594

Open
Andezion wants to merge 1 commit into
masterfrom
fix/elements-block-header-overread
Open

Andezion wants to merge 1 commit into
masterfrom
fix/elements-block-header-overread

Conversation

Andezion commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Summary

Follow up to #9485, which fixed truncated Bitcoin blocks. The same kind of bad block still crashed the Elements/Liquid header parser:

  • The challenge and dynafed fields were hashed before pull() checked the length. A truncated header caused a heap over-read, then a NULL dereference (sha256_update(shactx, NULL, 4))
  • A zero-length pull() after an earlier failure hit assert(p)
  • The extension-space and signblock witness counts come straight from the block, so a bad varint could loop up to 2^64 times

Separately, for all chains, a huge tx count made tal_arr() overflow and abort
As in #9485, this needs the chain backend to serve a bad block. A peer cannot trigger it

Fix

  • Add pull_and_hash(), which hashes only the bytes that pull() returns, and use it for all hashed header fields
  • Make pull() fail cleanly when the cursor is already NULL
  • Stop the two count-driven loops once the data runs out
  • Reject a tx count larger than the remaining bytes

Testing

run-bitcoin_block_from_hex now builds small liquid-regtest blocks (with and without dynafed) and checks that each one parses and that every truncation of it is rejected. It also checks huge extension space, signblock-witness and tx counts. Disabling any single part of the fix makes the test abort, segfault or hang

Important

26.09 FREEZE August 5th: Non-bugfix PRs not ready by this date will wait for 26.12.

RC1 is scheduled on August 17th

The final release is scheduled for September 7th.

Checklist

Before submitting the PR, ensure the following tasks are completed. If an item is not applicable to your PR, please mark it as checked:

  • The changelog has been updated in the relevant commit(s) according to the guidelines.
  • Tests have been added or modified to reflect the changes.
  • Documentation has been reviewed and updated as needed.
  • Related issues have been listed and linked, including any that this PR closes.
  • Important All PRs must consider how to reverse any persistent changes for tools/lightning-downgrade

Andezion self-assigned this Oct 1, 2026
Andezion added the Status::Ready for Review The work has been completed and is now awaiting evaluation or approval. label Oct 1, 2026
Andezion force-pushed the fix/elements-block-header-overread branch from 8d09ab2 to b3cc1d1 Compare October 1, 2026 15:12

This branch has not been deployed

No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Status::Ready for Review The work has been completed and is now awaiting evaluation or approval.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant


Back | FazBrowse Home | New Git URL