Crypto
Home›Crypto›Market Structure›Bitcoin Lightning Docker images may have skipped secur…
Bitcoin Lightning Docker images may have skipped security fixes
Core Lightning maintainers said four Docker image tags shipped unpatched binaries while reporting version v26.06.7, and users were told to verify image digests and pull replaced tags.
Core Lightning maintainers said four Docker image tags for Bitcoin Lightning delivered binaries that did not include the v26.06.7 security fixes, even though the images reported version v26.06.7 at startup. The affected tags were identified as v26.06.7, latest, v26.06.7-vls, and latest-vls.
According to CryptoSlate, the unpatched images were served between Aug. 28 at 16:04 UTC and Sept. 1, with no precise end time given. Maintainers said they have replaced the images and removed references to the incorrect manifests, but users who kept a faulty image could not rely on the startup version to confirm the patch arrived.
The notice directs operators to check local image integrity by inspecting the image digest, because startup output alone will not prove which manifest a container is actually running. For standard images, maintainers also provided docker pull commands for elementsproject/lightningd:v26.06.7 and elementsproject/lightningd:latest, while VLS users were told their VLS_CLN_VERSION setting must match v26.06.7 or remote_hsmd_socket will refuse to start.
CryptoSlate added that the v26.06.7 release had a 14 day source publication embargo tied to a planned Sept. 11 disclosure, and maintainers warned that GitHub’s automatically attached source-code archives during the embargo are not the patched source. Users pinned to v26.06.6 or earlier were described as escaping the packaging mistake, with the security fixes belonging to v26.06.7.
Latest closeBitcoin $79,310.40 ▲1.1%