KX
← All projectsKrux

Krux

Open-source signing firmware for Kendryte K210 devices.

BitcoinHardware walletsNormal
Repository coverage

216 commits in the local evidence base

Every captured commit receives deterministic security triage and a separate communication-quality score. Security candidates and broader second-pass signals receive full-patch Ollama analysis.

58security candidates41second-pass queue65AI analyses
39commits · 30 days
59commits · 60 days
100commits · 180 days
216commits · 365 days
Backfill bands
Aug 5 → Feb 6116 seen6 candidatesComplete
Feb 6 → Jun 639 seen3 candidatesComplete
Jun 6 → Jul 622 seen1 candidatesComplete
Jul 6 → Aug 538 seen5 candidatesComplete
Commit communication

Does the history explain itself?

Message quality measures whether a commit identifies its scope, purpose, rationale, testing, and supporting references. It does not change the security-severity score.

65/100 average clarity
59Strong · 80–100
62Adequate · 60–79
79Thin · 40–59
16Opaque · 0–39
6security candidates with opaque commit messaging
Read the scoring rubric →
Developer activity

Who is changing the project?

Public Git author strings; identities are not independently verified.

DeveloperCommitsCandidatesAnalyzedHigh riskMessage avg.
Odudex291415272
odudex892929159
Tads361010063
qlrd1622082
kdmukai422066
tadeubas411038
kkdao1204083
Jean Do600078
Naman015501060
bitcoisas500066
Naman Gupta200079
SatsCzar200062
Analysis record

Published AI watches

Last scanned 51 minutes ago

Moderate 66 AI analysisMessage 45 · Thin
KX KruxKrux BitcoinHardware wallets

Merge branch 'release-26.08.0'

This is a routine release merge for Krux firmware (version 26.08.0). It includes several genuine security fixes: a heap buffer overflow in camera-based entropy generation for a discontinued device, stricter fee calculation when signing Bit…

Heap buffer overflow fix in camera entropy module (discontinued Maix Bit only)PSBT fee calculation stricter checks and unverified-input-amount warningStored mnemonic file corruption now preserved instead of overwritten
be5eda28by odudex+4335−3028123 files
Vendor flagged security relevance
Informational 0 AI analysisMessage 40 · Thin
KX KruxKrux BitcoinHardware wallets

chore(Maixpy): bump cUR

This commit appears to be a routine version bump of a component called 'cUR' inside the MaixPy firmware build. No actual code changes are visible in the provided diff, and the commit message gives no indication of a security fix or vulnera…

74d6ed40by odudex+1−11 file
No security note in commit
Informational 2 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

chore: bump MaixPy with updated glyphs

This commit appears to update a submodule or dependency called MaixPy to a newer version that includes updated visual glyphs (small icons/symbols). The title and message describe it as a routine maintenance chore, not a security fix. No ac…

a9329228by odudex+1−11 file
No security note in commit
Informational 15 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: register embed_fire in the bdftokff device list

This commit fixes a build-time font-generation script so that a newly supported device ('embed_fire') is recognized. Before the fix, the script printed an error but still produced the same font files. There is no security issue.

f15308e4by odudex+1−01 file
No security note in commit
Moderate 63 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

docs: add PSBT input amount fixes to CHANGELOG

This commit only updates the project's CHANGELOG.md to document earlier fixes related to PSBT (Partially Signed Bitcoin Transaction) fee and amount handling. It does not contain any code changes itself. The changelog entries describe secur…

Changelog documents prior PSBT fee/amount validation fixesMentions insufficient coordinator data as a security concernNo actual code or test changes in this commit
48920c31by odudex+4−01 file
Vendor flagged security relevance
Moderate 66 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: reject a PSBT whose outputs exceed its inputs

This commit fixes a bug in Krux, a Bitcoin signing device, where a malformed transaction whose outputs spend more than its inputs could be loaded and shown to the user. Normally such a transaction is impossible on the Bitcoin network, but …

Input validation gap in PSBT parsingUI rendering bug masking invalid transaction economicsPotential social-engineering / user-confusion attack
d6813d88by odudex+52−02 files
Vendor flagged security relevance
Moderate 62 AI analysisMessage 90 · Strong
KX KruxKrux BitcoinHardware wallets

feat: warn when PSBT input amounts cannot be verified

This commit adds a warning screen to Krux, a hardware signing device, when it is asked to sign a multi-input Bitcoin transaction where the amounts of some inputs cannot be independently verified. The risk is that a malicious transaction co…

New user-facing warning for unverified multi-input SegWit amountsDetection logic tied to BIP143 signature semantics and inp.is_verifiedDoes not enforce previous-transaction inclusion; user can still proceed
518b3314by odudex+159−24 files
Vendor flagged security relevance
High 78 AI analysisMessage 95 · Strong
KX KruxKrux BitcoinHardware wallets

fix: verify PSBT input amounts before showing the fee

This commit fixes a security flaw in Krux, a Bitcoin signing device. Before the fix, an attacker could trick the device into showing a low transaction fee on screen while actually signing a much higher fee. The fix makes the device verify …

Fixes fee-display/sighash amount mismatchAdds prevout txid hash verification for non_witness_utxoMandates non_witness_utxo for legacy inputs
fc808059by odudex+353−122 files
Vendor flagged security relevance
Moderate 55 AI analysisMessage 82 · Strong
KX KruxKrux BitcoinHardware wallets

chore: bump MaixPy with Shannon changes and RNG removal

This commit updates a bundled firmware component called MaixPy. The commit message says it fixes a 'Shannon heap overflow,' removes an unused random-number binding, and drops support for one hardware variant (Maix Bit). A heap overflow is …

Commit message explicitly mentions fixing a heap overflowRemoval of an unused cryptographic/randomness binding (os.urandom)Submodule bump only; no source-level patch visible in this commit
5c4ece9aby odudex+1−11 file
Vendor flagged security relevance
Moderate 52 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

fix: remove Maix Bit and CIF camera support

This commit removes support for an old, discontinued hardware device called the Maix Bit from the Krux Bitcoin wallet firmware. The commit message says the Maix Bit's camera resolution (CIF) was the only one that fed frames larger than QVG…

Buffer overflow / scratch buffer overflow claimed in commit message (49,152 bytes)Removal of vulnerable hardware code path rather than hardening the entropy moduleDiscontinuation of affected device reduces real-world exposure
8090ac73by odudex+11−1279 files
Vendor flagged security relevance
Informational 15 AI analysisMessage 90 · Strong
KX KruxKrux BitcoinHardware wallets

refactor: use native uUR on tests and simulator

This commit is a routine engineering cleanup: it removes a Python-only compatibility layer (a 'shim') used for testing and simulation, and makes the test environment use the same C-language UR encoder/decoder module that the real hardware …

2fe2f5f5by odudex+108−24919 files
No security note in commit
Moderate 62 AI analysisMessage 93 · Strong
KX KruxKrux BitcoinHardware wallets

fix: reject base58 address with unknown version byte in parse_address

This fix closes a hole where a Bitcoin address that looks valid (correct checksum) but belongs to no known network could be accepted by Krux's address parser. Before the patch, the parser only caught thrown errors; because the underlying l…

Input validation bypass fixedBase58 address version byte not validated before fixLibrary silent failure (None return) not handled by caller
63e8b8e5by kkdao+20−12 files
No security note in commit
Low 34 AI analysisMessage 62 · Adequate
KX KruxKrux BitcoinHardware wallets

refactor: narrow parse_address fallbacks to EmbitError in wallet.py

This change fixes a bug where pressing a device's cancel/back button during address parsing could be ignored or misreported as an 'invalid address' instead of letting the user exit. The code previously caught every possible error (includin…

Bare exception handler narrowed to specific library exceptionUser-triggered interrupt (KeyboardInterrupt) no longer swallowedRegression test added for interrupt propagation in both code branches
a5fb4737by kkdao+24−32 files
No security note in commit
Low 34 AI analysisMessage 62 · Adequate
KX KruxKrux BitcoinHardware wallets

refactor: catch Exception, not bare except, in parse_wallet fallbacks

This commit tightens error handling in Krux's wallet parsing. Previously, the code used bare 'except:' clauses that would catch everything, including KeyboardInterrupt and SystemExit. Those special exceptions should normally be allowed to …

Bare except clauses replaced with except Exception to avoid swallowing KeyboardInterrupt/SystemExitNew regression test ensures KeyboardInterrupt propagates through all parse_wallet fallback branchesComments explicitly call out untrusted input and interrupt propagation behavior
6f617710by kkdao+42−72 files
No security note in commit
Low 29 AI analysisMessage 85 · Strong
KX KruxKrux BitcoinHardware wallets

refactor: adapt UR decoding to cUR state machine API

This commit refactors how Krux handles animated QR codes in the 'UR' format. It swaps an older decoder API for a newer state-machine API. The visible change is that transient decoding errors are now ignored while scanning, and only termina…

Error-handling behavior change: transient UR decoder errors are now ignored instead of abortingTerminal error set is narrow (NO_RESULT, INVALID_CHECKSUM); other decoder error states may be silently droppedFirmware submodule MaixPy updated, indicating the actual C decoder API changed
f90219e3by odudex+80−74 files
No security note in commit
Informational 15 AI analysisMessage 95 · Strong
KX KruxKrux BitcoinHardware wallets

test: build embit's C libsecp256k1 for tests

This commit only changes how automated tests are run. It builds a C cryptography library during testing so the test environment matches the real firmware more closely. There is no change to the actual Krux firmware or wallet code, and no s…

ac3ea482by odudex+37−03 files
No security note in commit
Informational 15 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

docs: add generated mnemonic flow screenshots

This commit only updates user documentation. It adds new screenshots showing how to create a new wallet mnemonic and updates the script that automatically generates those screenshots. There are no code changes that affect security.

61807e7eby Naman015+39−38 files
No security note in commit
Informational 0 AI analysisMessage 57 · Thin
KX KruxKrux BitcoinHardware wallets

chore: update cUR and k_quirk

The commit title says it is a routine maintenance update ('chore') for two internal items named cUR and k_quirk in the MaixPy firmware file. No diff content is available, and no verified references were supplied, so there is no visible evi…

f4796afeby odudex+1−11 file
No security note in commit
Repository ledger

Explore captured commits

Expand any commit for its author, full message, clarity score, changed files, triage signals, analysis, and source link.

Security candidateEmbed Fire - update krux build scriptby odudex · e6b895e5 · Oct 30, 2025 · 2 filesMessage 45 · ThinInformational 15Details
Commit message · odudex

Embed Fire - update krux build script

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
boot or update path
AI analysis · Informational 15/100

This commit simply adds a new hardware device called 'Embed Fire' to the list of devices Krux builds firmware for during release builds. It is a build-script update with no visible security implications.

Security candidateEmbed Fire - update Maixpyby odudex · 9eb4ebe3 · Oct 30, 2025 · 4 filesMessage 35 · OpaqueInformational 15Details
Commit message · odudex

Embed Fire - update Maixpy

35/100 · OpaqueMessage clarity
✓ Descriptive subject! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
boot or update path
AI analysis · Informational 15/100

This commit is a routine version bump from 25.10.1 to 25.11.beta0 in three files: documentation config, Python package config, and source metadata. The actual firmware submodule 'firmware/MaixPy' is referenced as changed but its diff is not shown. There is no visible security-relevant code change in the supplied diff.

Security candidateNew Device: Embed Fire (#738)by Odudex · dd36f474 · Oct 30, 2025 · 31 filesMessage 86 · StrongInformational 15Details
Commit message · Odudex

New Device: Embed Fire (#738)

* add new device: Embed Fire

custom display initialization for Embed Fire

* add touchscreen tests
not only for Embed Fire

* Embed Fire added to simulator and docs (#53)

---------

Co-authored-by: Tads <tadeubas@gmail.com>

86/100 · StrongMessage clarity
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
boot or update path
AI analysis · Informational 15/100

This commit adds support for a new hardware device called 'Embed Fire' to the Krux Bitcoin signer firmware. It includes new display and touchscreen driver code, build/flash tooling updates, simulator support, documentation, and a large set of unit tests. There is no indication in the commit or supplied references that this change fixes or introduces a security vulnerability.

Security candidateRelease 25.10.1 (#757)by Odudex · 64212093 · Oct 30, 2025 · 10 filesMessage 74 · AdequateModerate 64Details
Commit message · Odudex

Release 25.10.1 (#757)

* BugFix: Passphrase (via encrypted mnemonic entropy) fails gracefully (#756)

* resolve bug found by @tadeubas around encrypted passphrases
In Cpython a UnicodeDecodeError was being caught/ignored by the ValueError,
while in MaixPy, a TypeError was being raised, not caught, bubbling up:
...whenever an encrypted passphrase returned bytes that could not be decoded to a string.
Symptoms:
on simulator: appeared as if NOT KEF or user declines to decrypt,
on k210: TypeError("Can't convert 'int' object to str implicitely",)

* Passphrases: Ensure they are ASCII strings

* better error handling for decrypted wallet descriptors

* Similar pattern fix for encrypted addresses that don't decode
decoding of plaintext data is done separately in it's on
try except block to catch decoding errors and fail early.

---------

Co-authored-by: odudex <odudex@proton.me>

* update version: 25.10.1

---------

Co-authored-by: Jean Do <117163651+jdlcdl@users.noreply.github.com>

74/100 · AdequateMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
Why it was queued
entropy or randomnessaccess controlsigning or wallet path
AI analysis · Moderate 64/100

This release fixes a bug in Krux, a Bitcoin signing device firmware. When a user scanned an encrypted QR code meant to provide a wallet passphrase, address, or wallet descriptor, the device could silently treat the raw encrypted bytes as the passphrase/data instead of showing an error. That could lead to the wrong Bitcoin wallet being derived, with no warning to the user. The patch adds proper error handling and now rejects non-ASCII passphrases.

AI review queueddocs: adjust deviced images adjust BULL coordinator labels and linksby odudex · 05bbb0c0 · Oct 28, 2025 · 3 filesMessage 77 · AdequateTriage 0Details
Commit message · odudex

docs: adjust deviced images
adjust BULL coordinator labels and links

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathdocumentation-only discountsecond-pass: security-sensitive path
AI review queueddocs: adjust deviced images adjust BULL coordinator labels and linksby odudex · 10a12c35 · Oct 28, 2025 · 3 filesMessage 77 · AdequateTriage 0Details
Commit message · odudex

docs: adjust deviced images
adjust BULL coordinator labels and links

77/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Uses a recognizable type or scope✓ Provides an explanatory body
Why it was queued
signing or wallet pathdocumentation-only discountsecond-pass: security-sensitive path
Lower-priorityre-add WonderK to changelog add missing minor changes from previous changelogby odudex · 142fd283 · Oct 27, 2025 · 1 fileMessage 65 · AdequateTriage 0Details
Commit message · odudex

re-add WonderK to changelog
add missing minor changes from previous changelog

65/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
Why it was queued
documentation-only discount
Lower-priorityadd TZT to action build IIby odudex · cae75bba · Oct 27, 2025 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · odudex

add TZT to action build II

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
Lower-priorityadd TZT to action build IIby odudex · 592db5fb · Oct 27, 2025 · 1 fileMessage 45 · ThinTriage 0Details
Commit message · odudex

add TZT to action build II

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
AI review queuedadd TZT to and remove bit from action build and release scriptby odudex · fadf12c9 · Oct 27, 2025 · 2 filesMessage 50 · ThinTriage 12Details
Commit message · odudex

add TZT to and remove bit from action build and release script

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
AI review queuedadd TZT to and remove bit from action build and release scriptby odudex · 7d792495 · Oct 27, 2025 · 2 filesMessage 50 · ThinTriage 12Details
Commit message · odudex

add TZT to and remove bit from action build and release script

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathsecond-pass: security-sensitive path
Lower-priorityFrench translation adjust by Jeanne and Jean Doby odudex · 3006727c · Oct 27, 2025 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · odudex

French translation adjust by Jeanne and Jean Do

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
translation-only discount
Lower-priorityFrench translation adjust by Jeanne and Jean Doby odudex · 72a46651 · Oct 27, 2025 · 2 filesMessage 45 · ThinTriage 0Details
Commit message · odudex

French translation adjust by Jeanne and Jean Do

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
translation-only discount
Lower-priorityUpdate docs with note about improved SD card compatibilityby tadeubas · 9b8774a6 · Oct 26, 2025 · 1 fileMessage 50 · ThinTriage 0Details
Commit message · tadeubas

Update docs with note about improved SD card compatibility

50/100 · ThinMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
documentation-only discount
AI review queuedadd bull bitcoin to docsby tadeubas · 0b3f38eb · Oct 25, 2025 · 2 filesMessage 38 · OpaqueTriage 0Details
Commit message · tadeubas

add bull bitcoin to docs

38/100 · OpaqueMessage clarity
✓ Subject identifies a change✓ Names a concrete action or component! No meaningful explanatory body
Why it was queued
signing or wallet pathdocumentation-only discountsecond-pass: opaque commit messagesecond-pass: security-sensitive path
Lower-priorityFix mnemonic printing issue with long words (#751)by Tads · 47d3eb21 · Oct 25, 2025 · 7 filesMessage 73 · AdequateTriage 0Details
Commit message · Tads

Fix mnemonic printing issue with long words (#751)

* Fix mnemonic printing issue with long words

* fix device error when displaying backup as word numbers

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
Lower-priorityFix mnemonic printing issue with long words (#751)by Tads · ae240f04 · Oct 25, 2025 · 7 filesMessage 73 · AdequateTriage 0Details
Commit message · Tads

Fix mnemonic printing issue with long words (#751)

* Fix mnemonic printing issue with long words

* fix device error when displaying backup as word numbers

73/100 · AdequateMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
AI review queuedupdate versionby odudex · 9214d5ec · Oct 24, 2025 · 3 filesMessage 18 · OpaqueTriage 0Details
Commit message · odudex

update version

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
Security candidateupdate Maixpy fontsby odudex · f9e1f7d5 · Oct 24, 2025 · 1 fileMessage 28 · OpaqueInformational 3Details
Commit message · odudex

update Maixpy fonts

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
boot or update path
AI analysis · Informational 3/100

This commit is described as updating fonts in the MaixPy firmware component. No actual code diff is available, and there are no verified references linking this change to any security issue. Based solely on the provided materials, there is no evidence this is a security fix or introduces a vulnerability.

Security candidateupdate Maixpy fontsby odudex · fb9cc51f · Oct 24, 2025 · 1 fileMessage 28 · OpaqueInformational 2Details
Commit message · odudex

update Maixpy fonts

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body! Opaque security-relevant change
Why it was queued
boot or update path
AI analysis · Informational 2/100

This commit is described as updating fonts in the MaixPy firmware component. No actual code diff is available, and there are no verified references linking the change to any security issue. Based solely on the provided materials, there is no evidence this is a security fix or introduces a vulnerability.

AI review queuedupdate changelogby odudex · 24ae72fd · Oct 24, 2025 · 1 fileMessage 18 · OpaqueTriage 0Details
Commit message · odudex

update changelog

18/100 · OpaqueMessage clarity
✓ Subject identifies a change! Too few words to establish purpose! No meaningful explanatory body
Why it was queued
documentation-only discountsecond-pass: opaque commit message
AI review queuedup version to beta3by odudex · 03374b23 · Oct 24, 2025 · 3 filesMessage 28 · OpaqueTriage 0Details
Commit message · odudex

up version to beta3

28/100 · OpaqueMessage clarity
✓ Subject identifies a change! No meaningful explanatory body
Why it was queued
second-pass: opaque commit message
AI review queuedFix and update device docs, datum sequence, and images (#748)by Tads · 4de2cac1 · Oct 24, 2025 · 26 filesMessage 83 · StrongTriage 0Details
Commit message · Tads

Fix and update device docs, datum sequence, and images (#748)

* fix docs datum + imgs

* Add tools > touchscreen description in docs

* added more coverage

83/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
Why it was queued
second-pass: unusually broad change
Lower-priorityXOR pt-BR adjust update beta versionby odudex · 00a292f4 · Oct 22, 2025 · 5 filesMessage 45 · ThinTriage 0Details
Commit message · odudex

XOR pt-BR adjust
update beta version

45/100 · ThinMessage clarity
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
Security candidateXOR doesn’t display invalid mnemonic lengths for user selection (#747)by Tads · bfbdaec5 · Oct 22, 2025 · 32 filesMessage 81 · StrongInformational 24Details
Commit message · Tads

XOR doesn’t display invalid mnemonic lengths for user selection (#747)

* XOR doesn’t display invalid mnemonic lengths for user selection

* XOR prompt msg now warns about passphrase

* XOR fix incorrect fingerprint displayed when using passphrase

81/100 · StrongMessage clarity
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Links an issue, advisory, or supporting reference
Why it was queued
access control
AI analysis · Informational 24/100

This commit fixes two user-facing bugs in Krux's 'mnemonic XOR' feature. First, when asking the user to pick a mnemonic length, it now only shows the length that matches the currently loaded wallet (12 or 24 words), preventing the user from accidentally selecting an incompatible length. Second, it now warns the user that the wallet passphrase and descriptor will be discarded before starting the XOR operation, and it corrects the fingerprint shown after the XOR so it no longer incorrectly includes the old passphrase. These are usability and correctness fixes rather than remote-exploitable security holes.