A parsing vulnerability in lnd's onion processing logic led to a DoS vector due to excessive memory allocation.
The issue was patched in lnd v0.17.0. Users should update to a version >= v0.17.0 to be protected.
Detailed blog post: https://morehouse.github.io/lightning/lnd-onion-bomb/
Developer discussion: https://delvingbitcoin.org/t/dos-disclosure-lnd-onion-bomb/979
{
"severity": "HIGH",
"nvd_published_at": "2024-06-20T23:15:52Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-20"
],
"github_reviewed_at": "2024-06-20T19:18:25Z"
}