wallet2: bounds check additional derivations in is_out_to_acc
What changed, and why it matters
This commit adds a safety check in Monero's wallet code before accessing a list of 'additional derivations' by output index. Previously, if the list was shorter than expected, the code could read past its end (an out-of-bounds read). The patch throws a controlled wallet error instead of crashing or reading invalid memory. The most likely risk is a wallet crash or incorrect output detection when processing malformed or unusual transaction data, rather than direct theft of funds.
Apply the patch. It is a low-risk, defensive fix. Users running wallet software built from source before this commit should update. No immediate emergency response is indicated because exploitation appears limited to denial-of-service or output misclassification.
Security signals we found
Bounds check added to out-of-bounds vector access
Defensive exception rather than silent memory read
Located in transaction output ownership scanning path
Evidence from the diff
In wallet2::is_out_to_acc(), before indexing additional_derivations[output_index], the patch now verifies output_index < additional_derivations.size(). Without this check, a mismatch between the number of outputs and the number of additional derivations supplied could cause an out-of-bounds read of a std::vector. The function is used during output scanning/ownership checks, so the consequence is at most a crash or misclassification of an output, not key leakage or arbitrary code execution from this site alone.
Changed components
src/wallet/wallet2.cppwallet2::is_out_to_accInspect captured patch +2 / −0
diff --git a/src/wallet/wallet2.cpp b/src/wallet/wallet2.cpp
index 834679f..6b1144d 100644
--- a/src/wallet/wallet2.cpp
+++ b/src/wallet/wallet2.cpp
@@ -12084,6 +12084,8 @@ bool wallet2::is_out_to_acc(const cryptonote::account_public_address &address, c
if (!found && !additional_derivations.empty())
{
+ THROW_WALLET_EXCEPTION_IF(output_index >= additional_derivations.size(), error::wallet_internal_error,
+ "wrong number of additional derivations");
const crypto::key_derivation &additional_derivation = additional_derivations[output_index];
if (out_can_be_to_acc(view_tag_opt, additional_derivation, output_index))
{
Why this scored 58/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.