Executive Summary
Facts Only
* Unfunded-channel requests could crash vulnerable nodes without on-chain BTC expenditure.
* Saved channel records could exhaust memory upon restart following a crash.
* Eclair v0.14.1 fixed these flaws in July.
* Researcher Erick Cestari published findings on September 30.
* The vulnerability affected Eclair versions v0.14.0 and earlier.
* A malicious peer could accumulate saved requests without broadcasting funding or paying on-chain fees.
* One benchmark showed a node exhausted 4 GB of Java virtual machine heap after approximately 47 minutes 43 seconds with accumulated channel database rows.
* Patches were merged in July, with v0.14.1 shipping July 29, and v0.14.3 released September 14.
* The second bug involved a channel-opening race leading to orphaned processes consuming memory or CPU.
Full Take
From the original · CryptoSlate
Quick Take - New Eclair disclosures describe unfunded channel requests that could crash vulnerable nodes without on-chain BTC expenditure. - Saved channel records could exhaust memory again on restart, turning an initial crash into a recovery problem. - Eclair v0.14.1 fixed these flaws in July, while ACINQ recommends the later v0.14.3 security release.Read the full story at cryptoslate.com
Sentinel — Human
The text functions as a precise, technical summary of software security vulnerabilities and patch history, exhibiting the detailed attribution and nuanced context characteristic of human-authored specialized reporting.
