|

Core Lightning patches critical security flaws and a Bitcoin payment bug

Core Lightning v26.06.9 comparison showing the v26.06.8 message-budget regression repair, shutdown protection for forwarded funds, and rune, configuration, disclosure and development-build details.

Core Lightning, software program for operating Bitcoin Lightning payment nodes, has launched v26.06.9 with security fixes and a restore for a regression that might delay channel visitors on busy nodes operating v26.06.8.

GitHub lists the new release as revealed Oct. 7, whereas its versioned changelog carries an Oct. 6 date.

The replace provides operators who put in v26.06.8 a contemporary choice on upgrading, following the Sept. 27 revoked-channel penalty flaw that was fastened in v26.06.7. The newest patch provides fixes and addresses a regression launched by that later model.

Bitcoin payment delays and shutdown threat

In v26.06.8, routine gossip, pings, and onion messages counted towards a CPU finances meant for gossip queries. On busy nodes, that accounting may throttle friends and delay channel visitors, in accordance with the maintainers.

V26.06.9 reserves that finances for gossip queries, so bizarre messages now not devour it, eradicating the documented reason for this throttling. The regression described by maintainers issues busy nodes operating Core Lightning v26.06.8.

Related Reading

Onslaught of AI-found bugs forces Bitcoin’s Core Lightning into a secret 14-day emergency lockdown


The changelog additionally describes a repair for a payment contract (HTLC) that reaches its deadline whereas a channel is shutting down. V26.06.9 now force-closes the channel in that scenario, stopping forwarded funds from being misplaced if the payment is fulfilled late.

For an operator forwarding funds, this fixes a funds-protection drawback when payment deadlines and channel shutdown overlap.

Core Lightning v26.06.9 comparison showing the v26.06.8 message-budget regression repair, shutdown protection for forwarded funds, and rune, configuration, disclosure and development-build details.
Core Lightning v26.06.9 fixes a message-budget regression and provides shutdown, permission, and configuration safeguards.

Other fixes implement the bounds carried by runes used to authorize calls, so a restricted rune can now not create an unrestricted one or relist blacklisted runes. Restrictions on the corresponding creation and blocklisting strategies now additionally cowl the invokerune and destroyrune aliases.

The listconfigs command now masks a number of delicate values, together with restoration data and Bitcoin RPC passwords, for each caller. The setconfig command closes a path for injecting configuration strains by way of persistent possibility values.

The fixes can be found instantly, however maintainers have briefly held again security checks to make exploit growth more durable and give operators extra time to improve.

Nodes which have run grasp can’t downgrade to a 26.06.x launch as a result of their database schema is newer. The launch additionally reiterates that twin funding stays experimental and discourages zero-confirmation channels with untrusted friends.

Maintainers urge Core Lightning customers, together with these on v26.06.8, to improve to v26.06.9 as quickly as sensible.

The put up Core Lightning patches critical security flaws and a Bitcoin payment bug appeared first on CryptoSlate.

Similar Posts