correct an off-by-one move in BIP32 derivation parsing
fixed in public source; rollout not reverified
details
Finding IDs
F-LEDGER-BTC-BIP32-001
Status
fixed in public source; rollout not reverified
Disclosure date
Note
extract_bip32_derivation changes the memmove length from out_data_length - d + 1 to out_data_length - d. This is a different callsite from F-LEDGER-BTC-MERKLE-001, but both mappings share the same upstream commit; they are not two independent patch artifacts. Mapping is based on source comparison. Release inclusion and device rollout were not independently checked.
F-LEDGER-BTC-BIP32-001: Memory safety. A BIP32 buffer move has an off-by-one boundary error. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.