AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Cryptographic libraries

cryptonote_basic: fix add_extra_nonce_to_tx_extra() length

Public commit record

What the developer wrote

Authored by jeffro256

55/100 · Thin
cryptonote_basic: fix add_extra_nonce_to_tx_extra() length

Reviewed-by: selsta <selsta@sent.at>
Reviewed-by: SChernykh
✓ Specific, descriptive subject✓ Provides an explanatory body
The short version

What changed, and why it matters

This commit fixes a bug in how Monero builds the 'extra nonce' field inside transaction metadata. Previously, the code always reserved only 2 bytes for the length header, which is wrong for larger nonces because the protocol uses a variable-length integer (varint) that can take more than 1 byte. The patch now correctly calculates how many bytes the length needs and writes it as a proper varint. The bug could corrupt transaction extra data or cause parsing failures when nonces larger than 127 bytes are used, but the maximum allowed nonce size (255 bytes) limits the damage. There is no public statement from the Monero Project calling this a security issue, and no independent researcher is credited.

Recommended action

Treat as a correctness fix and include in normal release testing. Review callers of add_extra_nonce_to_tx_extra() to confirm no other code relies on the old fixed-size layout. Run the new unit tests. If this function is reachable from network-parsed inputs, consider a lightweight audit of tx_extra parsing for similar varint length assumptions elsewhere.

Security signals we found

01

Buffer sizing bug in transaction metadata serialization

02

Incorrect use of fixed 1-byte length where variable-length integer is required

03

Potential tx_extra corruption or parse failure for nonce sizes > 127

04

New unit tests added to cover varint length calculation and tx_extra helpers

05

No vendor security advisory or CVE referenced in commit

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.