AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 48 Cryptographic libraries

Merge pull request #11385

Public commit record

What the developer wrote

Authored by tobtoht

58/100 · Thin
Merge pull request #11385

887c865 mnemonics/polyseed: wipe stack buffers before returning (jpk68)

ACKs: thomasbuilds, selsta
✓ Descriptive subject✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit adds cleanup of three additional memory buffers in Monero's seed-phrase key-stretching code. Before the change, leftover copies of intermediate secrets could remain in stack memory after the function finished. An attacker who could read process memory (for example, through another vulnerability or a memory dump) might recover parts of a wallet's seed-phrase secret. The patch wipes those buffers before returning, reducing that exposure.

Recommended action

Treat as a low-to-moderate hardening fix. Include in routine security updates. No emergency response is indicated because exploitation requires an additional memory-read primitive and the patch is additive rather than fixing an active bug.

Security signals we found

01

Sensitive intermediate key material left in stack memory after function return

02

Use of sodium_memzero to clear cryptographic buffers

03

PBKDF2 implementation handling mnemonic-derived secrets

Risk score

Why this scored 48/100

Our methodology →
Potential impact 12/30
Exploitability 10/25
Stealth signal 8/15
Affected reach 7/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.