Fix: check hwdev.generate_output_ephemeral_keys result
What changed, and why it matters
This commit fixes a bug where Monero's transaction creation code did not check whether a hardware wallet device successfully generated the one-time public key and view tag for a transaction output. If the hardware device call failed, the code would continue using uninitialized cryptographic values, which could lead to creating an invalid or insecure transaction. The fix adds an explicit error check that aborts transaction creation if the key generation fails.
Apply the patch. Additionally, audit other hwdev call sites for unchecked return values and consider whether uninitialized-variable risks exist elsewhere in transaction construction paths.
Security signals we found
Use of uninitialized cryptographic output (out_eph_public_key, view_tag) on failure path
Missing return-value check on security-critical hardware wallet API call
Potential creation of malformed/invalid transaction output if hwdev call fails
Fix is defensive and localized to transaction construction path
Evidence from the diff
In src/cryptonote_core/cryptonote_tx_utils.cpp, the function constructing transaction outputs previously ignored the return value of hwdev.generate_output_ephemeral_keys(). That function populates out_eph_public_key and view_tag. On failure, these stack-allocated variables would remain uninitialized and then be used to construct a tx_out via set_tx_out(). The patch captures the boolean return value and uses CHECK_AND_ASSERT_MES(r, false, …) to fail the transaction construction cleanly instead of proceeding with undefined data.
Changed components
src/cryptonote_core/cryptonote_tx_utils.cppTransaction output construction / tx_out generationHardware wallet integration (hwdev.generate_output_ephemeral_keys)Inspect captured patch +2 / −1
diff --git a/src/cryptonote_core/cryptonote_tx_utils.cpp b/src/cryptonote_core/cryptonote_tx_utils.cpp
index b84e946..566738b 100644
--- a/src/cryptonote_core/cryptonote_tx_utils.cpp
+++ b/src/cryptonote_core/cryptonote_tx_utils.cpp
@@ -466,11 +466,12 @@ namespace cryptonote
crypto::public_key out_eph_public_key;
crypto::view_tag view_tag;
- hwdev.generate_output_ephemeral_keys(tx.version,sender_account_keys, txkey_pub, tx_key,
+ const bool r = hwdev.generate_output_ephemeral_keys(tx.version,sender_account_keys, txkey_pub, tx_key,
dst_entr, change_addr, output_index,
need_additional_txkeys, additional_tx_keys,
additional_tx_public_keys, amount_keys, out_eph_public_key,
use_view_tags, view_tag);
+ CHECK_AND_ASSERT_MES(r, false, "Failed to generate output ephemeral keys");
tx_out out;
cryptonote::set_tx_out(dst_entr.amount, out_eph_public_key, use_view_tags, view_tag, out);
Why this scored 59/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.