THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2024-38359

Lightning Network Daemon Onion Bomb

Assigner:GitHub_M
Reserved:2024-06-14
Published:2024-06-20
Updated:2024-06-21

Description

The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead to a DoS vector due to excessive memory allocation. The issue was patched in lnd v0.17.0. Users should update to a version > v0.17.0 to be protected. Users unable to upgrade may set the `--rejecthtlc` CLI flag and also disable forwarding on channels via the `UpdateChanPolicyCommand`, or disable listening on a public network interface via the `--nolisten` flag as a mitigation.



MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-20: Improper Input Validation

Product status

< 0.17.0
affected

References

https://github.com/lightningnetwork/lnd/security/advisories/GHSA-9gxx-58q6-42p7

https://delvingbitcoin.org/t/dos-disclosure-lnd-onion-bomb/979

https://github.com/lightningnetwork/lnd/releases/tag/v0.17.0-beta

https://lightning.network

https://morehouse.github.io/lightning/lnd-onion-bomb

cve.org CVE-2024-38359

nvd.nist.gov CVE-2024-38359

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-38359