AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 51 Cryptographic libraries

use byte-safe isalpha in epee json value parser

Public commit record

What the developer wrote

Authored by alhudz

45/100 · Thin
use byte-safe isalpha in epee json value parser
✓ Descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This commit fixes a bug in Monero's JSON parser where it used the standard C 'isalpha' function to decide if a value looks like a keyword such as 'true', 'false', or 'null'. On some systems, passing a negative number (which can happen when the input contains high-byte non-ASCII characters like certain UTF-8 bytes) to the standard 'isalpha' can cause undefined behavior or be misclassified as alphabetic. The patch replaces the unsafe call with a custom byte-safe version that only looks at the raw byte value. A new test confirms that a value starting with a non-ASCII byte is now rejected instead of being treated as a keyword.

Recommended action

Apply the patch and run the new unit test. Review other uses of isalpha/isdigit in the epee parser and serialization code for similar byte-safety issues, especially where char values from untrusted network input are passed to C library character classification functions.

Security signals we found

01

Undefined behavior in standard isalpha() when passed negative char values

02

Potential parser misclassification of malformed UTF-8 input as JSON keyword literals

03

Locale-dependent character classification replaced with byte-safe lookup table

04

New unit test explicitly exercises rejection of non-ASCII leading byte in value position

Risk score

Why this scored 51/100

Our methodology →
Potential impact 12/30
Exploitability 10/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.