What changed, and why it matters
This commit fixes an off-by-one error in a wallet fee calculation. The original code allowed an index equal to the array size, which could read one element past the end of a fee lookup table. This could cause the wallet to use incorrect fee data or crash, but the commit message only describes it as a 'faulty bounds check' with no security framing.
Review whether fee_algorithm_index can ever reach the maximum value in practice and consider adding a regression test. The fix itself should be applied; it is a correct bounds correction.
Security signals we found
Off-by-one bounds check leading to potential out-of-bounds array access
Out-of-bounds read in fee calculation path
No explicit security framing in commit message
Evidence from the diff
In wallet2::get_fee_multiplier(), the bounds check used > instead of >= when comparing fee_algorithm_index against std::size(fee_steps). Because C++ arrays are zero-indexed, a value equal to the size is out of bounds. The fix changes the comparison to >=, preventing an out-of-bounds read into fee_steps[fee_algorithm_index].maximum_priority. The change is minimal and correct, but the patch is a single-line fix with no additional hardening or tests shown.
Changed components
src/wallet/wallet2.cppwallet2::get_fee_multiplier()fee_steps array accessInspect captured patch +1 / −1
diff --git a/src/wallet/wallet2.cpp b/src/wallet/wallet2.cpp
index dc41292..9b568eb 100644
--- a/src/wallet/wallet2.cpp
+++ b/src/wallet/wallet2.cpp
@@ -8478,7 +8478,7 @@ uint64_t wallet2::get_fee_multiplier(fee_priority priority, fee_algorithm fee_al
}
const auto fee_algorithm_index = fee_algorithm_utilities::as_integral(fee_algorithm);
- THROW_WALLET_EXCEPTION_IF(fee_algorithm_index < 0 || fee_algorithm_index > static_cast<int>(std::size(fee_steps)), error::invalid_priority);
+ THROW_WALLET_EXCEPTION_IF(fee_algorithm_index < 0 || fee_algorithm_index >= static_cast<int>(std::size(fee_steps)), error::invalid_priority);
// 1 to 3/4 are allowed as priorities
const fee_priority max_priority = fee_steps[fee_algorithm_index].maximum_priority;
Why this scored 46/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.