reject all negative merkleized-map return values before using their length
fixed in public source; rollout not reverified
details
Finding IDs
F-LEDGER-BTC-NEGRC-002
Status
fixed in public source; rollout not reverified
Disclosure date
Note
txhashes and sign_psbt callers check < 0 rather than only == -1, preventing other error returns from being used as lengths. Mapping is based on the reported callsites and public diff. Release inclusion and device rollout were not independently checked.
F-LEDGER-BTC-NEGRC-002: Memory safety. A negative return value becomes an unsigned buffer length. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.