AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Bitcoin

Merge pull request #697 from Foundation-Devices/SFT-8171-bip39-prefix-bounds

Public commit record

What the developer wrote

Authored by mjg-foundation

73/100 · Adequate
Merge pull request #697 from Foundation-Devices/SFT-8171-bip39-prefix-bounds

SFT-8171: bounds accounting in BIP39 prefix matching
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit fixes two related bugs in the BIP39 word lookup feature used when entering seed words on the Passport hardware wallet. First, the code could write past the end of its result buffer when many words matched a short prefix, because it did not reserve space for the comma separator and string terminator. Second, a negative 'max matches' value from the Python side would be treated as a huge positive number, potentially causing an out-of-bounds write. The patch adds proper bounds checks, rejects negative counts, and adds unit tests to verify safe behavior.

Recommended action

Treat this as a security fix and include it in the next firmware release. Verify the new unit tests pass on device, and consider fuzzing `get_words_matching_prefix()` with random prefixes, buffer sizes, and match limits to ensure no further off-by-one issues remain.

Security signals we found

01

Out-of-bounds write in C string buffer during prefix matching

02

Integer signedness issue: negative max_matches wraps to large unsigned value

03

Missing terminator/separator accounting in length check

04

Unit tests added to verify bounds invariants and negative input rejection

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.