AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 57 Cryptographic libraries

wallet2: validate legacy transfer output indices

Public commit record

What the developer wrote

Authored by selsta

60/100 · Adequate
wallet2: validate legacy transfer output indices

Reported by xmrack and the MAGIC Monero Fund.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides an explanatory body
The short version

What changed, and why it matters

This commit adds a safety check when loading older Monero wallet data. It ensures that a stored 'output index' (which points to a specific coin within a past transaction) does not point past the number of outputs that transaction actually has. Without this check, a malformed or manipulated old wallet file could reference a non-existent output, potentially causing crashes or undefined behavior when the wallet later uses that index.

Recommended action

Treat as a security-hardening fix for legacy wallet deserialization. Include in release notes and backport to maintained branches. Users with old wallet caches should ensure they are on a patched version before loading untrusted wallet files. No immediate network-wide action is indicated.

Security signals we found

01

Out-of-bounds index validation added during deserialization

02

Legacy data format specifically targeted (ver < 4)

03

Throws archive exception to abort loading invalid state

04

Reported by external parties (xmrack and MAGIC Monero Fund)

Risk score

Why this scored 57/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.