reject truncated calldata sizes and offsets in generic clear signing
fixed in public source; rollout not reverified
details
Finding IDs
F-LEDGER-ETH-GCS-U16-OFFSET-SPLICE-001
Status
fixed in public source; rollout not reverified
Disclosure date
Note
path_ref, path_leaf and path_array reject nonzero high bytes before reading a 16-bit size or offset. This matches the reported truncation vector; it does not establish fixes for other plugin or nested-offset reports. Public credit, a fixed release and device rollout are not asserted.
F-LEDGER-ETH-GCS-U16-OFFSET-SPLICE-001: Display / action mismatch. A truncated calldata offset changes which content is displayed before signing. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Security area (1seal assessment): Semantics. Truncating a calldata offset can make the displayed field differ from the field selected by the full encoded offset. Reviewed 23 Sep 2026.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.