reject a derivation step at the array capacity boundary
fixed in public source; rollout not reverified
details
Finding IDs
F-LEDGER-BTC-OBO-001
Status
fixed in public source; rollout not reverified
Disclosure date
Note
wallet parsing changes the derivation-length check from > to >= before writing a step. The reported boundary condition matches this public diff. Release inclusion and device rollout were not independently checked; public credit is not asserted.
F-LEDGER-BTC-OBO-001: Memory safety. Capacity handling has an off-by-one buffer error. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Security area (1seal assessment): Memory safety. The corrected comparison prevents an array write when the derivation buffer is already full. Reviewed 23 Sep 2026.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.