bound preimage writes by the output buffer capacity
fixed in public source; rollout not reverified
details
Finding IDs
F-LEDGER-BTC-PREIMAGE-001
Status
fixed in public source; rollout not reverified
Disclosure date
Note
call_get_preimage now rejects an oversized preimage and checks buffer writes. The finding-to-patch mapping is based on the reported callsite and public diff, not public attribution of this finding ID. A fixed release and device rollout were not independently checked.
F-LEDGER-BTC-PREIMAGE-001: Memory safety. Preimage writes require an explicit destination-buffer bound. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.