AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 28 Cryptographic libraries

wallet2: avoid std::out_of_range on a truncated tx set blob

Public commit record

What the developer wrote

Authored by Thomas

73/100 · Adequate
wallet2: avoid std::out_of_range on a truncated tx set blob

parse_unsigned_tx_from_str() and parse_tx_from_str() strip the magic,
then read the version byte and call s.substr(1) without checking a
version byte follows. A blob equal to just the magic leaves an empty
remainder, so s.substr(1) throws std::out_of_range instead of the
function returning false. Require magic + a version byte first.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit fixes a minor crash bug in Monero's wallet code. When the wallet tried to read a transaction data blob that contained only the file-type 'magic' header and nothing else, it would throw an uncaught out-of-range exception instead of cleanly reporting 'bad data.' The patch makes the wallet check that at least one byte follows the magic before reading it, turning the crash into a normal error return.

Recommended action

Apply the patch. It is a low-risk, defensive fix. Consider also auditing other parse_*_from_str helpers for similar missing length checks after magic stripping.

Security signals we found

01

Denial-of-service vector: unhandled std::out_of_range exception on malformed input

02

Input-validation gap: magic prefix checked without ensuring minimum remaining length

03

Exception-safety fix in transaction deserialization paths

Risk score

Why this scored 28/100

Our methodology →
Potential impact 5/30
Exploitability 4/25
Stealth signal 3/15
Affected reach 4/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.