AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Cryptographic libraries

tx_pool: fix use-after-free in prune() - txid was a reference to an item which was later deleted in remove_tx_from_transient_lists(), and txid was used after that

Public commit record

What the developer wrote

Authored by SChernykh

73/100 · Adequate
tx_pool: fix use-after-free in prune()
- txid was a reference to an item which was later deleted in remove_tx_from_transient_lists(), and txid was used after that
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit fixes a use-after-free bug in Monero's transaction pool (tx_pool). The code was storing a reference to a transaction ID, then deleting the underlying data structure that held that ID, and later still using the now-stale reference. The fix simply copies the ID value instead of holding a reference, so it remains valid after deletion. This is a memory-safety bug that could cause crashes or, in the worst case, be exploited to manipulate transaction processing, though the commit itself does not describe any exploit.

Recommended action

Apply the patch. It is a one-line, low-risk change that copies a 32-byte hash by value. After applying, run transaction-pool pruning tests and fuzz/stress-test mempool eviction paths to confirm stability. No additional mitigation is described as necessary.

Security signals we found

01

use-after-free

02

dangling reference to container element

03

transaction pool memory corruption

04

potential crash or undefined behavior in core daemon

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.