LND Out-of-Memory via Brontide Write Allocations
Published September 21, 2026
| Affected Product | Affected Versions | Patched Versions |
|---|---|---|
| lnd | < 0.20.0-beta | 0.20.0-beta |
Impact
lnd’s encrypted transport layer (Brontide) allocated fresh buffers on every message written. A peer that drove a high volume of message traffic could force enough allocation to exhaust the node’s memory and cause an OOM kill.
There is no fund-loss path. The node restarts cleanly when the attacker disconnects.
Severity
Scored against the Lightning Labs severity taxonomy:
| Dimension | Score | Reasoning |
|---|---|---|
| Impact | Low | OOM crash, operator-recoverable. |
| Attack Vector | High | Network. Any connected peer; no channel required. |
| Exploitability | High | Reliable with sustained traffic against a default configuration. |
| Virality | Low | Per-victim sustained connection; nothing propagates. |
Result: T3. Rule 3 (Impact = Low, base T3); no promotion because Virality is not High.
Patches
Fixed in lnd v0.20.0-beta via lnd#10183, which eliminates the per-write allocations. Users should update to v0.20.0-beta or later.
The fix was not backported to the v0.19 line, which reached end of life on 2026-06-05; operators on v0.19 or earlier should upgrade to a maintained release.
Disclosure timeline
- Reported by Matt Morehouse and Erick Cestari.
- Fix merged 2025-09-24; released in lnd v0.20.0-beta on 2025-11-20.
- Public disclosure: 2026-09-21.