cryptonote_core: remove Boost serialization for tx_source_entry
What changed, and why it matters
This commit removes the Boost serialization code for a Monero internal data structure called tx_source_entry. It deletes about 20 lines of code that described how this structure is converted to/from a serialized format. The change appears to be a cleanup or hardening step, not a fix for an active vulnerability. There is no direct evidence in the commit that this change addresses a security bug, and no public references were provided.
Treat as routine hardening/cleanup unless additional context emerges. Review whether tx_source_entry is still serialized elsewhere or whether any remaining code paths expect Boost serialization for this type. Monitor Monero release notes and security advisories for follow-up disclosure.
Security signals we found
Removal of serialization code for a sensitive transaction-input structure
Reduction of Boost serialization attack surface
No explicit security claim or CVE reference in commit
No advisory or incident reference supplied
Evidence from the diff
The patch removes BOOST_CLASS_VERSION and a boost::serialization::serialize template specialization for cryptonote::tx_source_entry in src/cryptonote_core/cryptonote_tx_utils.h. It also removes two Boost serialization header includes (boost/serialization/vector.hpp and boost/serialization/utility.hpp). The tx_destination_entry serialization remains. The tx_source_entry structure holds transaction input data such as real output index, amount, ringCT data, and multisig key info. Removing Boost serialization for this type reduces the attack surface for deserialization-based bugs (e.g., memory corruption, type confusion, or object injection via Boost serialization), but the commit itself does not describe a specific vulnerability or demonstrate exploitability.
Changed components
src/cryptonote_core/cryptonote_tx_utils.hcryptonote::tx_source_entry serializationInspect captured patch +2 / −20
diff --git a/src/cryptonote_core/cryptonote_tx_utils.h b/src/cryptonote_core/cryptonote_tx_utils.h
index d3b8bfe..582b023 100644
--- a/src/cryptonote_core/cryptonote_tx_utils.h
+++ b/src/cryptonote_core/cryptonote_tx_utils.h
@@ -1,4 +1,4 @@
-// Copyright (c) 2014-2024, The Monero Project
+// Copyright (c) 2014-2026, The Monero Project
//
// All rights reserved.
//
@@ -29,9 +29,8 @@
// Parts of this file are originally copyright (c) 2012-2013 The Cryptonote developers
#pragma once
+
#include "cryptonote_basic/cryptonote_format_utils.h"
-#include <boost/serialization/vector.hpp>
-#include <boost/serialization/utility.hpp>
#include "ringct/rctOps.h"
namespace cryptonote
@@ -151,29 +150,12 @@ namespace cryptonote
}
-BOOST_CLASS_VERSION(cryptonote::tx_source_entry, 1)
BOOST_CLASS_VERSION(cryptonote::tx_destination_entry, 2)
namespace boost
{
namespace serialization
{
- template <class Archive>
- inline void serialize(Archive &a, cryptonote::tx_source_entry &x, const boost::serialization::version_type ver)
- {
- a & x.outputs;
- a & x.real_output;
- a & x.real_out_tx_key;
- a & x.real_output_in_tx_index;
- a & x.amount;
- a & x.rct;
- a & x.mask;
- if (ver < 1)
- return;
- a & x.multisig_kLRki;
- a & x.real_out_additional_tx_keys;
- }
-
template <class Archive>
inline void serialize(Archive& a, cryptonote::tx_destination_entry& x, const boost::serialization::version_type ver)
{
Why this scored 11/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.