LND Onion Bomb Denial of Service - Matt Morehouse

LND versions prior to 0.17.0 are vulnerable to a DoS attack where malicious onion packets cause the node to instantly run out of memory (OOM) and crash. If you are running an LND release older than this, your funds are at risk! Update to at least 0.17.0 to protect your node.

Severity

It is critical that users update to at least LND 0.17.0 for several reasons.

  • The attack is cheap and easy to carry out and will keep the victim offline for as long as it lasts.
  • The source of the attack is concealed via onion routing. The attacker does not need to connect directly to the victim.
  • Prior to LND 0.17.0, all nodes are vulnerable. The fix was not backported to the LND 0.16.x series or earlier.

Vulnerability

Details

Fix & Prevention

More Resources

Sponsors

USD/BTC