Ledger fixes two Ethereum signing bugs in 1.22.3

Ledger released Ethereum app 1.22.3 on Aug. 25 to close two signing bugs left after 1.22.2; the company wrote the interleaving flaw had already been patched and reported no user losses.

Ledger published Ethereum app 1.22.3 on Aug. 25 to address two transaction-signing vulnerabilities that remained after the Aug. 13 release of version 1.22.2. The update was distributed through Ledger Live and targets weaknesses in how the device app constructs and approves Ethereum transactions.

One of the issues, tracked as LSB-023, involves command interleaving a compromised host can use to change transaction parameters after they are shown on the device but before signing. Ledger’s security team wrote: “No Ledger user was hacked.” The company added the demonstration that reproduced the interleaving flaw was run against an older build and that LSB-023 was fixed in app version 1.22.2.

Two additional signing paths remained until the 1.22.3 update. LSB-024 affected how the app processed arrays of operations during clear signing. The app read the number of operations using a 16-bit value but stored the remaining count in an 8-bit field. In Ledger’s proof of concept, an array containing 257 operations caused the counter to wrap to one, so the device displayed only the final operation while the signature authorized the entire batch. Exploitation required a compromised host and an unusually large, attacker-controlled operation array. Ledger tested the scenario on a private network fork and reported no real-user losses.

LSB-025 affected the token-payment path used by Ledger’s Exchange application during token swaps. The app verified the token, quantity and destination but did not confirm that the requested action was a payment. A malicious or compromised swap provider could substitute a token approval with matching parameters and have it signed without an additional device prompt. Ledger noted an approval itself does not transfer funds and that the bug could not create unlimited approvals, switch the token, or grant permission to an arbitrary address. The company reported no evidence the swap-related flaw was exploited.

Internal records show the fixes for LSB-024 and LSB-025 were merged on May 5 and May 25, respectively, before the Aug. 13 release of 1.22.2. Ledger has not published an explanation for why those fixes were not included in 1.22.2. Chief Technology Officer Charles Guillemet wrote that reproducing an already-patched flaw did not amount to “hacking Ledger.” Ledger urged users to install Ethereum app 1.22.3 or later via Ledger Live and to verify the app version on their device, and warned that updating device firmware alone does not replace the Ethereum application or install these signing fixes.

Articles by this author