A parsing vulnerability in lnd's onion processing logic led to a DoS vector due to excessive memory allocation.
The issue was patched in lnd v0.17.0. Users should update to a version >= v0.17.0 to be protected.
Detailed blog post: https://morehouse.github.io/lightning/lnd-onion-bomb/
Developer discussion: https://delvingbitcoin.org/t/dos-disclosure-lnd-onion-bomb/979
{ "nvd_published_at": "2024-06-20T23:15:52Z", "cwe_ids": [ "CWE-20" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-06-20T19:18:25Z" }