github ElementsProject/lightning v26.06.9
v26.06.9 Quantum-Resistant Lightning Channel VI

3 hours ago

This 26.06.9 point release includes a set of bug fixes alongside fixes for vulnerabilities responsibly reported by a number of sources, and fixes a gossip regression introduced in 26.06.8. We strongly recommend upgrading to this release.

As with 26.06.8, there is no embargo period: the release and its fixes are available immediately. We have again temporarily withheld the tests for the security fixes, to make it harder to quickly turn the fixes into working exploits and to give users and network participants more time to upgrade before more technical detail is published.

The full list of changes is in the CHANGELOG.

We strongly encourage everyone to upgrade to 26.06.9 as soon as practical.

Highlights

  • Security fixes in channel reestablishment, splicing, HTLC handling during shutdown, onion handling, onchaind, gossip range queries, runes and setconfig, plus several remote-crash and hardening fixes.
  • Gossip CPU throttle regression fixed: in 26.06.8, busy nodes could throttle their peers on ordinary gossip, pings and onion messages, delaying channel traffic. Now only gossip queries count against the budget.
  • New: reproducible arm64 and armv7 binaries for Ubuntu 22.04, 24.04 and 26.04, alongside the existing amd64 builds. Each architecture has its own signed manifest: SHA256SUMS-v26.06.9 (amd64 and source zip), SHA256SUMS-v26.06.9-arm64 and SHA256SUMS-v26.06.9-armv7, each with an .asc carrying the maintainers' signatures.

Notes for operators

  • Runes: a rune with restrictions can no longer create a new rune without them (createrune without a rune), nor relist blacklisted runes (blacklistrune with relist). Use an unrestricted rune for those. invokerune and destroyrune are now checked as createrune and blacklistrune.
  • listconfigs now shows ... instead of the value of wallet, recover, tor-service-password, bitcoin-rpcpassword and the old bookkeeper-db, for every caller.
  • Splicing: when we accept a splice, we now enforce the negotiated feerate on the splice transaction.
  • Dual funding (--experimental-dual-fund) remains experimental. Zero-conf channels with peers you do not trust are discouraged.
  • Nodes that have run development (master) builds cannot downgrade to a 26.06.x release: the database schema is newer.

Verifying the release

Check the signatures against the manifest explicitly (pass both files), then the checksums:

gpg --verify SHA256SUMS-v26.06.9.asc SHA256SUMS-v26.06.9
sha256sum -c SHA256SUMS-v26.06.9 --ignore-missing

Use SHA256SUMS-v26.06.9-arm64 / -armv7 and their .asc for the ARM tarballs. The maintainers' keys are listed in SECURITY.md; instructions for reproducing the builds are in the reproducible builds guide.

Thanks

This point release includes fixes for issues responsibly reported by:

Thanks to our Open Source Contributors for their assistance with the fixes included in .9

And to the maintaining team who worked tirelessly on this release:

Don't miss a new lightning release

NewReleases is sending notifications on new releases.