LND Panic on Malformed DNS Seed Response
Published September 21, 2026
| Affected Product | Affected Versions | Patched Versions |
|---|---|---|
| lnd | < 0.20.2-beta and 0.21.0-beta | 0.20.2-beta, 0.21.1-beta |
Impact
lnd’s DNS peer bootstrapper, enabled by default on mainnet, falls back to a TCP SRV lookup when the primary UDP query fails. The fallback accepted any response with a success code and then asserted that every answer record was an SRV record using Go’s single-value type assertion. A response containing any other record type, such as an A or CNAME record, caused an unrecovered panic in the bootstrap goroutine and terminated the daemon.
DNS is unauthenticated, so an on-path attacker, or a malicious or compromised DNS seed operator, could drop the UDP query to force the fallback and then return a crafted TCP response. The crash was repeatable whenever the node bootstrapped peers, at startup or whenever active peers fell below target.
There is no fund-loss path. The node restarts cleanly, although a persistently
hostile seed would trigger the crash again at the next bootstrap. Operators who
cannot upgrade can set nobootstrap=true to disable DNS peer bootstrapping.
Severity
Scored against the Lightning Labs severity taxonomy:
| Dimension | Score | Reasoning |
|---|---|---|
| Impact | Low | Process crash, operator-recoverable by restart. |
| Attack Vector | High | Network. DNS is unauthenticated; no relationship with the victim is required. |
| Exploitability | Med | Requires an on-path position or control of a seed the victim queries, and the fallback path must be reached. |
| Virality | Med | A compromised seed serves the same crafted answer to every node that falls back to it, a replayable template; an on-path attacker reaches only the nodes on that path. Nothing propagates node to node. |
Result: T3. Rule 3 (Impact = Low, base T3); no promotion because Virality is not High.
Patches
Fixed via lnd#10914 and released on both maintained lines: v0.21.1-beta (2026-06-30) and v0.20.2-beta (2026-07-08). Users should update to the patched release on their line.
Disclosure timeline
- Identified internally by the Lightning Labs security team.
- Fix merged 2026-06-24; released in lnd v0.21.1-beta on 2026-06-30 and v0.20.2-beta on 2026-07-08.
- Public disclosure: 2026-09-21.