This 26.06.8 point release includes a set of bug fixes alongside fixes for vulnerabilities responsibly reported by a number of sources. We strongly recommend upgrading to this release.
There is no embargo period for 26.06.8. The release and the associated fixes are available immediately. However, we have temporarily withheld a small number of tests to make it more difficult for prospective attackers to identify, reverse-engineer, and exploit the underlying vulnerabilities.
This measure is intended to give users and network participants more time to upgrade before additional technical detail becomes available.
Notes for operators
- Dual funding (
--experimental-dual-fund) remains experimental. Zero-conf channels with peers you do not trust are discouraged. - Nodes that have run development (master) builds cannot downgrade to a 26.06.x release: the database schema is newer.
Thanks
This point release includes fixes for issues responsibly reported by:
- Bitcoin Red Team
- @0xaudron
- @erickcestari
- @Ahmadsm2005
- @whkim0
- @ksedgwic
- @jaonoctus
- @vincenzopalazzo
- @labrat-guy
- @michael1011
- @project-loupe
- @Crypt-iQ
- @btweenthebars
- and reporters who chose to remain anonymous
To the open source contributors who assisted with fixes and reviews:
- @rustyrussell
- @ksedgwic
- @ddustin
- @niftynei
- @vincenzopalazzo
- @Amperstrand
- @morehouse
- @ThomsenDrake
- @w3lld1
And to the maintaining team who worked on this release: