AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 60 Bitcoin

SFT-8171: bounds accounting in BIP39 prefix matching

Public commit record

What the developer wrote

Authored by Jack

73/100 · Adequate
SFT-8171: bounds accounting in BIP39 prefix matching

get_words_matching_prefix() worked in whole entries and did not account
for the separators it writes, so its accounting did not hold for every
buffer size and match count. Compute the room needed up front and count
the separator, and move the match cap into the loop condition so a count
of zero means zero rather than unlimited.

Also reject a negative count in the binding rather than converting it to
an unsigned one.

Shipped callers ask for at most 10 matches and are unaffected.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit fixes a buffer-size accounting bug in the Passport hardware wallet's BIP39 word lookup feature. The function that returns matching seed-phrase words could write slightly past the end of its output buffer in some edge cases, and a negative match count could be misinterpreted as 'unlimited matches.' The patch corrects the size math, caps matches inside the loop, and rejects negative counts. The commit message says current callers are unaffected, and new unit tests verify the bounds.

Recommended action

Treat as a security-relevant hardening fix. Merge the patch, run the new unit tests, and consider whether any other language bindings cast user-supplied counts directly to unsigned types without validation.

Security signals we found

01

Off-by-one / separator accounting error in buffer filling

02

Signed-to-unsigned conversion of user-supplied count in language binding

03

Potential buffer over-write in BIP39/bytewords prefix helper

04

Addition of unit tests covering bounds and negative-count rejection

Risk score

Why this scored 60/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.