AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 60 Cryptographic libraries

Blockchain: fix wrong block_weight in handle_get_objects

Public commit record

What the developer wrote

Authored by SChernykh

73/100 · Adequate
Blockchain: fix wrong block_weight in handle_get_objects

- When there are missing IDs, blocks.size() != arg.blocks.size(), so arg.blocks can't be indexed by `i` - the indices will be wrong, the wrong weight will be returned to some peer and this peer will ban our node.

Use `bl.second` instead of `arg.blocks[i]`. Also it saves one DB query per returned block.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit fixes a bug in Monero's blockchain code where a node could accidentally report the wrong block size (weight) to a peer. The bug happened because the code used a mismatched index when some requested blocks were missing. A peer receiving the wrong weight might ban the node, hurting network connectivity. The fix also removes an unnecessary database lookup.

Recommended action

Apply the patch. Nodes should upgrade to avoid being incorrectly banned by peers due to stale or mismatched block weight data. No immediate incident response beyond normal patching is indicated.

Security signals we found

01

Incorrect index mapping between request and response arrays

02

Wrong block metadata returned to peer

03

Potential peer-triggered node ban (denial of service / isolation)

04

Fix saves a database query per returned block

Risk score

Why this scored 60/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.