AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 57 Cryptographic libraries

Merge pull request #11359

Public commit record

What the developer wrote

Authored by tobtoht

58/100 · Thin
Merge pull request #11359

52a7ff3 cryptonote_core: reject duplicate tx hashes before pool lookup (selsta)

ACKs: jpk68, SChernykh, PyXMR2025
✓ Descriptive subject✓ Provides an explanatory body✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This change adds a safety check when a Monero node packages a block for relay to other nodes. Before this patch, if a block somehow contained the same transaction hash twice, the node would not notice and could produce an invalid or malformed block package. The fix detects duplicate transaction hashes and throws an error instead of silently continuing. The commit message does not describe this as a security fix, so its security relevance is uncertain, but duplicate-hash bugs in consensus-related code can sometimes be exploited to cause network disruption or inconsistent state.

Recommended action

Treat as a hardening fix with possible denial-of-service or consensus-integrity implications. Review whether duplicate `tx_hashes` can reach `get_block_complete_entry()` from untrusted input (e.g., a miner-submitted block or a relayed block) and confirm the throw is handled safely by callers. No immediate emergency response is indicated, but include in routine security release notes if a new version is prepared.

Security signals we found

01

Consensus-adjacent validation added to block serialization path

02

Duplicate identifier check prevents potential inconsistent block packaging

03

No explicit security framing in commit or vendor references

Risk score

Why this scored 57/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.