wallet2: add parse multisig tx sanity checks
What changed, and why it matters
This commit adds two safety checks to the Monero wallet code that parses multisig transactions. It now rejects multisig transactions that have no inputs ('vin') and no 'sources'. Without these checks, a malformed or malicious multisig transaction string might have been accepted for further processing, potentially causing crashes, incorrect signing behavior, or confusion in the multisig workflow. The change is small and defensive.
Treat as a low-to-moderate hardening fix. Include in routine release notes; no urgent advisory is required unless further analysis shows the empty-input case is reachable from untrusted network data or can crash/sign incorrectly. Users running multisig wallets should update with the next maintenance release.
Security signals we found
Input validation hardening in transaction parsing
Defensive check against empty transaction inputs
Multisig code path targeted by patch
Evidence from the diff
In wallet2::parse_multisig_tx_from_str(), after deserializing a multisig transaction string, the code already verified selected transfer indices and that sources.size() equals tx.vin.size(). This patch adds two CHECK_AND_ASSERT_MES guards ensuring tx.vin and construction_data.sources are non-empty. This prevents processing of degenerate multisig transactions lacking inputs, which could otherwise propagate through signing/export/import loops and trigger logic errors or assertion failures downstream.
Changed components
src/wallet/wallet2.cppwallet2::parse_multisig_tx_from_strInspect captured patch +2 / −0
diff --git a/src/wallet/wallet2.cpp b/src/wallet/wallet2.cpp
index 1f70f22..a9a2629 100644
--- a/src/wallet/wallet2.cpp
+++ b/src/wallet/wallet2.cpp
@@ -8185,6 +8185,8 @@ bool wallet2::parse_multisig_tx_from_str(std::string multisig_tx_st, multisig_tx
for (size_t idx: ptx.construction_data.selected_transfers)
CHECK_AND_ASSERT_MES(idx < m_transfers.size(), false, "Transfer index out of range");
CHECK_AND_ASSERT_MES(ptx.construction_data.sources.size() == ptx.tx.vin.size(), false, "Mismatched sources/vin sizes");
+ CHECK_AND_ASSERT_MES(!ptx.tx.vin.empty(), false, "Multisig tx has no inputs");
+ CHECK_AND_ASSERT_MES(!ptx.construction_data.sources.empty(), false, "Multisig tx has no sources");
}
return true;
Why this scored 44/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.