AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
High 76 Cryptographic libraries

cryptonote_basic: keep additional derivations aligned in key image helper

Public commit record

What the developer wrote

Authored by Cole Munz

73/100 · Adequate
cryptonote_basic: keep additional derivations aligned in key image helper

generate_key_image_helper only appended to additional_recv_derivations when
generate_key_derivation succeeded. A tx pubkey that is not a valid point makes
that call fail, so every later derivation shifted down one slot.

is_out_to_acc_precomp indexes that vector by the output index, so once the
list is short the lookup either falls off the bounds check or reads the
derivation belonging to a different output. Either way the helper reports that
the output does not belong to the address, and the wallet cannot build a key
image for an output it owns. Anyone who can put a transaction in front of the
wallet chooses those pubkeys.

The main tx pubkey a few lines up already handles a failed derivation by
keeping its slot and padding with identity, and wallet2 does the same in the
three places it builds this list (wallet2.cpp:2393, :7887, :13397). Do it here
too.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This patch fixes a bug in how Monero wallets build key images for transaction outputs they own. When a transaction contained an invalid extra public key, the wallet would misalign its internal list of cryptographic derivations. This caused the wallet to either look at the wrong entry or fail to recognize its own output, preventing it from creating a key image. Because anyone can craft a transaction with such an invalid key, this could be used to stop a wallet from spending its own funds. The fix pads the failed derivation with a placeholder so the list stays aligned with output indexes.

Recommended action

Apply the patch and run the included unit test. Review other call sites that build additional_recv_derivations to ensure consistent alignment behavior. Consider adding fuzzing or validation for malformed additional_tx_public_keys in transaction parsing.

Security signals we found

01

Off-by-one / index misalignment in cryptographic derivation list

02

Missing placeholder for failed key derivation causing vector desynchronization

03

Denial-of-spend: wallet cannot construct key image for owned output

04

Attacker-controlled transaction public keys trigger the failure

05

Inconsistent handling between main tx pubkey and additional tx pubkeys

Risk score

Why this scored 76/100

Our methodology →
Potential impact 22/30
Exploitability 18/25
Stealth signal 12/15
Affected reach 10/15
Confidence 9/10
Evidence quality 5/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.