AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 42 Cryptographic libraries

wallet2: trim stale transfer maps after output imports

Public commit record

What the developer wrote

Authored by selsta

50/100 · Thin
wallet2: trim stale transfer maps after output imports
✓ Specific, descriptive subject✓ Names a concrete action or component! No meaningful explanatory body
The short version

What changed, and why it matters

This Monero wallet patch cleans up internal lookup tables (key-image and public-key indexes) when the list of owned transaction outputs is shrunk, for example during an output import. Without the cleanup, those indexes could point to entries that no longer exist, which could cause the wallet to crash or behave incorrectly when it later tries to spend or display funds. The patch also repairs any stale indexes when loading an older wallet cache that has never been refreshed from a node.

Recommended action

Treat as a defensive correctness fix. Review whether stale m_pub_keys entries could affect transaction construction or output selection, and consider adding an explicit bounds check before any direct use of these map values. Backport to maintained releases because stale indexes in existing wallets are repaired on cache load only if the wallet has never refreshed from a node.

Security signals we found

01

Out-of-bounds index retained in wallet lookup maps after container shrink

02

Potential wallet crash or incorrect spend selection due to stale key-image / public-key mapping

03

Repair-on-load for legacy wallet caches that predate the fix

04

No explicit bounds check added to map lookups; relies on trimming and existing throw

Risk score

Why this scored 42/100

Our methodology →
Potential impact 12/30
Exploitability 8/25
Stealth signal 6/15
Affected reach 7/15
Confidence 6/10
Evidence quality 3/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.