This 26.06.8 point release includes a set of bug fixes alongside fixes for vulnerabilities responsibly reported by a number of sources. We strongly recommend upgrading to this release.
Our responsibility to the network, impact and associated risks remain front of mind for everyone involved, not least the maintaining and remediation team, who have worked tirelessly to triage reports, resolve issues, review, and compile this release.
Unlike 26.06.7, there is no embargo period for 26.06.8. The release and the associated fixes are available immediately. However, we have temporarily withheld a small number of tests to make it more difficult for prospective attackers to quickly identify, reverse-engineer, and exploit the underlying vulnerabilities in the wild. This measure is intended to give users and network participants more time to upgrade before additional technical detail becomes available.
We strongly encourage everyone to upgrade to 26.06.8 as soon as practical.
Notes for operators
- Dual funding (
--experimental-dual-fund) remains experimental. Zero-conf channels with peers you do not trust are discouraged. - Nodes that have run development (master) builds cannot downgrade to a 26.06.x release: the database schema is newer.
Thanks
This point release includes fixes for issues responsibly reported by:
- Bitcoin Red Team
- @0xaudron
- @erickcestari
- @Ahmadsm2005
- @whkim0
- @ksedgwic
- @jaonoctus
- @vincenzopalazzo
- @labrat-guy
- @michael1011
- @project-loupe
- @Crypt-iQ
- @btweenthebars
- and reporters who chose to remain anonymous
To the open source contributors who assisted with fixes and reviews:
- @rustyrussell
- @ksedgwic
- @ddustin
- @niftynei
- @vincenzopalazzo
- @Amperstrand
- @morehouse
- @ThomsenDrake
- @w3lld1
And to the maintaining team who worked tirelessly on this release: