CVE-2024-38359
Lightning Network Daemon Onion Bomb
Severity Score
6.5
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead to a DoS vector due to excessive memory allocation. The issue was patched in lnd v0.17.0. Users should update to a version > v0.17.0 to be protected. Users unable to upgrade may set the `--rejecthtlc` CLI flag and also disable forwarding on channels via the `UpdateChanPolicyCommand`, or disable listening on a public network interface via the `--nolisten` flag as a mitigation.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-06-14 CVE Reserved
- 2024-06-20 CVE Published
- 2024-06-21 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://delvingbitcoin.org/t/dos-disclosure-lnd-onion-bomb/979 | X_refsource_misc | |
https://github.com/lightningnetwork/lnd/releases/tag/v0.17.0-beta | X_refsource_misc | |
https://github.com/lightningnetwork/lnd/security/advisories/GHSA-9gxx-58q6-42p7 | X_refsource_confirm | |
https://lightning.network | X_refsource_misc | |
https://morehouse.github.io/lightning/lnd-onion-bomb | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Lightningnetwork Search vendor "Lightningnetwork" | Lnd Search vendor "Lightningnetwork" for product "Lnd" | < 0.17.0 Search vendor "Lightningnetwork" for product "Lnd" and version " < 0.17.0" | en |
Affected
|