simplewallet: validate get_outs response size
What changed, and why it matters
This commit adds a safety check in Monero's command-line wallet. When the wallet asks the network node (daemon) for details about certain transaction outputs, it now verifies that the daemon actually returned the same number of results that were requested. Without this check, a malicious or buggy daemon could return fewer (or conceivably different) output records than expected, which might cause the wallet to misread ring member data when displaying or analyzing transactions. The patch is small and defensive; it does not by itself prove an exploitable vulnerability, but it closes a trust boundary gap between the wallet and the daemon.
Treat as a hardening fix with possible security relevance. Review whether other wallet RPC consumers perform similar response-size validation, and consider adding analogous checks to wallet2 and any GUI wallet paths that call get_outs. No CVE or advisory is supplied; do not assign one without vendor confirmation.
Security signals we found
Missing input/response validation at a daemon-wallet trust boundary
Potential for a malicious daemon to influence wallet ring-member processing via malformed RPC response
Defensive size check added after RPC call
Evidence from the diff
In simplewallet.cpp’s process_ring_members(), after calling get_outs() against the daemon, the patch validates that res.outs.size() equals req.outputs.size(). Previously the code iterated over res.outs assuming it matched the request. A mismatch could lead to index misalignment or missing ring-member metadata when the wallet later uses the returned block heights and keys. The change aborts with an error message if sizes differ. This is a partial, client-side hardening patch; it does not address any server-side root cause or demonstrate a full exploit chain.
Changed components
src/simplewallet/simplewallet.cppsimplewallet::process_ring_members()wallet2 RPC get_outs handlingInspect captured patch +5 / −0
diff --git a/src/simplewallet/simplewallet.cpp b/src/simplewallet/simplewallet.cpp
index e5b82d6..f3ceb3f 100644
--- a/src/simplewallet/simplewallet.cpp
+++ b/src/simplewallet/simplewallet.cpp
@@ -6098,6 +6098,11 @@ bool simple_wallet::process_ring_members(const std::vector<tools::wallet2::pendi
fail_msg_writer() << tr("failed to get output: ") << err;
return false;
}
+ if (res.outs.size() != req.outputs.size())
+ {
+ fail_msg_writer() << tr("daemon returned an invalid number of outputs");
+ return false;
+ }
// make sure that returned block heights are less than blockchain height
for (auto& res_out : res.outs)
{
Why this scored 59/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.