Breaking
EUUS Forces Destroy Five Iranian Oil Tankers Following Attacks on Navy WarshipPLHead of Hegseth's team in Poland. Talks about permanent US military basesEUOpenAI Agents Bypass Safety Parameters to Hijack German Wiki ForumAUMan shot dead in Sydney community centre carparkTRHonor Restarts Registration for MagicOS 11 Internal Beta ProgramAUAnthropic researcher quits over AI existential risk concernsARThe Taliban denied the presence of Masoud Azhar in Afghanistan, Chinese directives for artificial intelligence, and the opening of a bridge between Russia and North Korea.CNJiang Wanan Dabao's exchange trip to the United States stirred controversy. Zhou Xuan: It was the Beijing Municipal Government's Ethics Office that requested the Supervisory Yuan to investigate.CNXi Jinping had a phone call with British Prime Minister Beander to discuss bilateral relations and differencesRUZakharova called the arrest of the ship "Professor Molchanov" a well-thought-out operationEUUS Forces Destroy Five Iranian Oil Tankers Following Attacks on Navy WarshipPLHead of Hegseth's team in Poland. Talks about permanent US military basesEUOpenAI Agents Bypass Safety Parameters to Hijack German Wiki ForumAUMan shot dead in Sydney community centre carparkTRHonor Restarts Registration for MagicOS 11 Internal Beta ProgramAUAnthropic researcher quits over AI existential risk concernsARThe Taliban denied the presence of Masoud Azhar in Afghanistan, Chinese directives for artificial intelligence, and the opening of a bridge between Russia and North Korea.CNJiang Wanan Dabao's exchange trip to the United States stirred controversy. Zhou Xuan: It was the Beijing Municipal Government's Ethics Office that requested the Supervisory Yuan to investigate.CNXi Jinping had a phone call with British Prime Minister Beander to discuss bilateral relations and differencesRUZakharova called the arrest of the ship "Professor Molchanov" a well-thought-out operation
BackCore Lightning Maintainers Warn of Unpatched Binaries in Docker Images
Core Lightning Maintainers Warn of Unpatched Binaries in Docker Images
Urgent
CryptoSlate48 minutes agoTech2 min read

Core Lightning Maintainers Warn of Unpatched Binaries in Docker Images

Four Docker image tags delivered unpatched binaries during the v26.06.7 release, requiring operators to manually verify image digests.

Quick Look

  • Core Lightning maintainers revealed that four image tags served unpatched binaries instead of v26.06.7 updates.
  • Operators are urged to manually verify image digests to ensure security fixes are properly applied.

AI-generated summary

Why It Matters

The Bitcoin Lightning software maintainers set a 14-day embargo on publishing source code, pointing to a planned Sept. 11 disclosure.

Font size

The Bitcoin Lightning software's maintainers say four image tags delivered unpatched binaries while reporting version v26.06.7 at startup, leaving affected users with another task: check the image digest and download a corrected image if it differs.

Some Core Lightning operators who attempted the v26.06.7 upgrade through Docker may still be missing its security fixes.

The updated release notice identifies the affected tags as v26.06.7, latest, v26.06.7-vls and latest-vls. They served images without the release's fixes between Aug. 28 at 16:04 UTC and Sept. 1. The notice gives no precise end time.

An automated build process published the images from a placeholder tag. Maintainers say they have replaced them and removed every tag's reference to the incorrect manifests. But an operator who retained a faulty image cannot rely on its startup version to confirm the patch arrived.

The Aug. 28 release set a 14-day embargo on publishing its source, pointing to a planned Sept. 11 disclosure. As of Sept. 8, the notice still describes that publication as upcoming. Maintainers say the delay gives operators time to upgrade before prospective attackers can reverse-engineer the fixes.

How to check the Docker image to fix the Lightning bug

Maintainers ask anyone who previously pulled one of the four tags to compare its digest, the image's identifying hash, against the corrected values:

Docker tagsCorrected digestv26.06.7, latestsha256:0421a5f0d1b2e1ad639edfa17d777816040e3850d91bae7f2d32186d9c1e6da4v26.06.7-vls, latest-vlssha256:6a5e05c13a65613f8c0fe3830c60248a6724e7206c1c23dd26ac2e98a3e72c1f

For the standard versioned image, the notice supplies this command to inspect the local image. Its output alone does not establish which image an existing container is running:

docker image inspect --format '{{index .RepoDigests 0}}' elementsproject/lightningd:v26.06.7

If the digest differs, its corresponding download command is:

docker pull elementsproject/lightningd:v26.06.7

The notice also supplies docker pull elementsproject/lightningd:latest for that tag. VLS users need the separate VLS digest in the table. Their VLS_CLN_VERSION setting must also match v26.06.7, or remote_hsmd_socket will refuse to start; the signer itself remains VLS v0.14.0.

Users pinned to v26.06.6 or earlier escaped this packaging mistake. The exemption concerns the faulty packaging; the new security fixes belong to v26.06.7.

The packaging correction changes the operator's immediate problem of an attempted upgrade may need to be checked again while that window remains open.

Another download trap exists during the embargo. GitHub's automatically attached source-code archives are not the v26.06.7 source, maintainers warn, so building those archives will not produce the advertised patched binaries.

Open Questions

  • What specific vulnerability was addressed in v26.06.7?
  • How many operators were affected by the unpatched images?

Related Topics

This article was originally published by CryptoSlate.

Related Stories

Blockstream in talks with hackers to recover $47 million in stolen Bitcoin from Liquid Network
Developing·

Blockstream in talks with hackers to recover $47 million in stolen Bitcoin from Liquid Network

Blockstream is in ongoing negotiations with hackers who exploited a flaw in Liquid Network's Elements software to withdraw approximately 4,000 BTC worth $320 million, aiming to recover the remaining 600 BTC valued at $47 million. The hackers returned 3,400 BTC on Monday but still hold 600 BTC. Liquid Network paused operations after the exploit, which involved unbacked L-BTC tokens being accepted as valid due to a transaction-level validation failure. The company confirmed no private keys were compromised and that functionary nodes were not hacked. Blockstream is preparing an emergency update to fix the vulnerability and restore network operations.

Decrypt
2 min read
More on this topicbitcoin