Core Lightning confirms multiple vulnerabilities, prepares security update

摘要:Core Lightning said several AI-generated vulnerability reports were valid and told node operators to upgrade promptly once the fix arrives.

Core Lightning, an open-source implementation of Bitcoins Lightning Network, has confirmed multiple vulnerabilities and urged node operators to install a forthcoming security update.

On Thursday, Core Lightning said it had been assessing a high volume of AI-generated Common Vulnerabilities and Exposures (CVE) reports and found that several are real. The project told operators not to shut down their nodes completely, but to restart them with “--offline,” which prevents payments from entering, leaving or routing through the node.

In a subsequent post, Core Lightning clarified that upgrading is its primary recommendation, while restarting with --offline is an alternative for operators who have not upgraded.

The guidance gives operators an alternative for protecting their nodes until they upgrade, without shutting down the underlying software entirely. Core Lightning has not disclosed the nature or severity of the vulnerabilities, published CVE identifiers or reported any related exploitation or losses.

Core Lightning said keeping the daemon active allows it to follow the Bitcoin blockchain and respond if a counterparty force-closes a channel, which a stopped node cannot do. Operators using --offline were advised to remove it after upgrading or their nodes will remain disconnected.

The newly confirmed flaws are separate from remote denial-of-service vulnerabilities disclosed in May and July, which were patched in earlier releases.

免责声明

本文观点仅代表作者个人观点,不构成本平台的投资建议,本平台不对文章信息准确性、完整性和及时性作出任何保证,亦不对因使用或信赖文章信息引发的任何损失承担责任
上一篇

Entropy 能成为第二个 Trade 吗? Pre-IPO 的竞争之战已打响

下一篇

WikiBit交易所跑路风险榜第6期Coincheck:被偷过5.3亿刀、被巨头收购、登上纳斯达克——日本“国民交易所”的冰与火之歌