simplewallet: fix crash in sweep commands when address is omitted
What changed, and why it matters
This patch fixes a crash in Monero's command-line wallet (simplewallet) when a user runs a 'sweep' command without providing a destination address. Before the fix, the wallet would try to read from an empty list of arguments, likely causing it to crash. The fix adds a simple check: if no address is given, it prints an error and shows usage instructions instead of crashing. This is a reliability bug, not a security vulnerability that allows theft or remote compromise.
Apply the patch. It is a low-risk, correct fix. No additional security response is indicated because the issue is a local crash requiring the wallet owner to run a malformed command, and there is no evidence it can be exploited for code execution or funds theft.
Security signals we found
Out-of-bounds / empty-container access in CLI wallet
Crash-only denial-of-service for the local wallet process
No input validation before parsing destination address
Patch is a guard check, not a full refactor
Evidence from the diff
The change adds an empty-vector guard in simple_wallet::sweep_main() before the code calls cryptonote::get_account_address_from_str_or_url() on local_args[0]. When the sweep command was invoked without an address, local_args was empty, so accessing local_args[0] produced undefined behavior (likely an out-of-bounds read/crash). The patch returns true after printing an error and usage. It is a local, client-side crash fix with no evidence of memory corruption exploitability or security boundary crossing.
Changed components
src/simplewallet/simplewallet.cppsimple_wallet::sweep_main()Monero CLI wallet sweep commandsInspect captured patch +7 / −0
diff --git a/src/simplewallet/simplewallet.cpp b/src/simplewallet/simplewallet.cpp
index 04bac19..4c8f8c9 100644
--- a/src/simplewallet/simplewallet.cpp
+++ b/src/simplewallet/simplewallet.cpp
@@ -6975,6 +6975,13 @@ bool simple_wallet::sweep_main(uint32_t account, uint64_t below, const std::vect
local_args.pop_back();
}
+ if (local_args.empty())
+ {
+ fail_msg_writer() << tr("No address given");
+ print_usage();
+ return true;
+ }
+
cryptonote::address_parse_info info;
if (!cryptonote::get_account_address_from_str_or_url(info, m_wallet->nettype(), local_args[0], oa_prompter))
{
Why this scored 30/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.