Coin Brief ENDE

Core Lightning 26.06.9 ships more security fixes and undoes a gossip throttle

Core Lightning released v26.06.9 on 7 October, a point release the maintainers strongly recommend upgrading to. It combines bug fixes, fixes for vulnerabilities responsibly reported by several sources, and a repair for a regression introduced in the previous release.

No embargo, tests withheld. As with 26.06.8, the fixes are public immediately, with no embargo period. The team has again temporarily withheld the tests for the security fixes, to make it harder to turn them quickly into working exploits and to give operators more time to upgrade before technical detail is published.

Where the security fixes are. Channel reestablishment, splicing, HTLC handling during shutdown, onion handling, onchaind, gossip range queries, runes and setconfig, plus several remote-crash and hardening fixes.

The regression. In 26.06.8, busy nodes could throttle their peers on ordinary gossip, pings and onion messages, delaying channel traffic. In 26.06.9, only gossip queries count against the CPU budget.

Core Lightning 26.06.9 ships more security fixes and undoes a gossip throttle
Core Lightning 26.06.9 ships more security fixes and undoes a gossip throttle — Coin Brief

New builds. Reproducible arm64 and armv7 binaries for Ubuntu 22.04, 24.04 and 26.04 join the existing amd64 builds, each architecture with its own signed SHA256SUMS manifest.

Operator notes.

  • A rune with restrictions can no longer create an unrestricted rune or relist blacklisted runes; those actions now need an unrestricted rune, and invokerune and destroyrune are checked like createrune and blacklistrune.
  • listconfigs now prints ... instead of the values of wallet, recover and tor-service-password.

This is the third security point release in the 26.06 line since late August; the 28 August release fixed a revoked-commitment penalty bug under a two-week embargo.