What changed, and why it matters
This commit adds cleanup of three additional memory buffers in Monero's seed-phrase key-stretching code. Before the change, leftover copies of intermediate secrets could remain in stack memory after the function finished. An attacker who could read process memory (for example, through another vulnerability or a memory dump) might recover parts of a wallet's seed-phrase secret. The patch wipes those buffers before returning, reducing that exposure.
Treat as a low-to-moderate hardening fix. Include in routine security updates. No emergency response is indicated because exploitation requires an additional memory-read primitive and the patch is additive rather than fixing an active bug.
Security signals we found
Sensitive intermediate key material left in stack memory after function return
Use of sodium_memzero to clear cryptographic buffers
PBKDF2 implementation handling mnemonic-derived secrets
Evidence from the diff
In src/mnemonics/polyseed/pbkdf2.c, crypto_pbkdf2_sha256 already zeroed Phctx and PShctx on exit. The patch extends sodium_memzero to hctx, U, and T, which are local stack buffers holding PBKDF2 intermediate state and block values. This is a defense-in-depth fix against stack-memory disclosure of key material derived from the mnemonic seed.
Changed components
src/mnemonics/polyseed/pbkdf2.ccrypto_pbkdf2_sha256 functionPolyseed mnemonic key derivationInspect captured patch +3 / −0
### src/mnemonics/polyseed/pbkdf2.c
@@ -82,4 +82,7 @@ crypto_pbkdf2_sha256(const uint8_t* passwd, size_t passwdlen,
}
sodium_memzero((void*)&Phctx, sizeof Phctx);
sodium_memzero((void*)&PShctx, sizeof PShctx);
+ sodium_memzero((void*)&hctx, sizeof hctx);
+ sodium_memzero((void*)U, sizeof U);
+ sodium_memzero((void*)T, sizeof T);
}Why this scored 48/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.