Core Lightning confirms multiple vulnerabilities, prepares security update
Core Lightning advised operators to use offline mode if they do not install the forthcoming update, keeping their nodes active but disconnected.
Core Lightning, an open-source implementation of Bitcoin’s Lightning Network, has recently confirmed multiple vulnerabilities and released a security update for node operators. Rather than shutting down their nodes entirely, operators were advised to use an offline mode, allowing their nodes to remain active but disconnected. Core Lightning, which assesses AI-generated Common Vulnerabilities and Exposures (CVE) reports, found that several vulnerable reports were genuine.
The primary recommendation is to upgrade the software, but restarting nodes with the "--offline" option provides an alternative for those who have not yet upgraded. This guidance aims to protect the nodes without completely turning off the software. Core Lightning has not disclosed the specifics or severity of the vulnerabilities, nor reported any related exploitation or losses.
The functionality of the daemon allows it to follow the Bitcoin blockchain and respond if a counterparty force-closes a channel, a task beyond the capabilities of a stopped node. Operators using the "--offline" mode are urged to remove it after upgrading, as their nodes will remain disconnected. These newly discovered flaws are separate from previously disclosed remote denial-of-service vulnerabilities, which were addressed in earlier releases.
Written by urgent.news from Cointelegraph's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.