Description
The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead to a DoS vector due to excessive memory allocation. The issue was patched in lnd v0.17.0. Users should update to a version > v0.17.0 to be protected. Users unable to upgrade may set the `--rejecthtlc` CLI flag and also disable forwarding on channels via the `UpdateChanPolicyCommand`, or disable listening on a public network interface via the `--nolisten` flag as a mitigation.
Published: 2024-06-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2003 The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead to a DoS vector due to excessive memory allocation. The issue was patched in lnd v0.17.0. Users should update to a version > v0.17.0 to be protected. Users unable to upgrade may set the `--rejecthtlc` CLI flag and also disable forwarding on channels via the `UpdateChanPolicyCommand`, or disable listening on a public network interface via the `--nolisten` flag as a mitigation.
Github GHSA Github GHSA GHSA-9gxx-58q6-42p7 Lightning Network Daemon (LND)'s onion processing logic leads to a denial of service
History

No history.

Subscriptions

Lightning Network Daemon Project Lightning Network Daemon
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T04:04:25.238Z

Reserved: 2024-06-14T14:16:16.465Z

Link: CVE-2024-38359

cve-icon Vulnrichment

Updated: 2024-06-21T12:34:40.955Z

cve-icon NVD

Status : Deferred

Published: 2024-06-20T23:15:52.700

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-38359

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses