What changed, and why it matters
This commit adds a safety check in the code that talks to USB hardware wallets (Ledger/Trezor-style devices via HID). Previously, when receiving a response in chunks, the code could keep writing past the end of a fixed-size buffer if a malicious or misbehaving device sent more data than expected. The new check stops this before each read, preventing a buffer overflow. The fix uses an assertion, which means the program will abort rather than continue in an unsafe state.
Apply the patch. Treat it as a security fix for the hardware wallet interaction layer. Users who interact with hardware wallets should upgrade. Consider whether the assertion is the right failure mode for production builds, or whether a graceful error return is preferable.
Security signals we found
Buffer overflow protection added in device I/O path
Missing bounds check before repeated chunked read
Fix targets HID hardware wallet communication
Uses assertion to enforce safety invariant
Evidence from the diff
In src/device/device_io_hid.cpp, the function reads HID responses from a hardware wallet into a fixed-size buffer in chunks of MAX_BLOCK bytes, advancing offset. Before this patch, there was no check that offset + MAX_BLOCK still fit within buffer. A device sending an oversized response could cause a heap or stack buffer overflow (depending on buffer allocation). The patch adds ASSERT_X(offset + MAX_BLOCK <= sizeof(buffer), ...), which aborts if the next chunk would exceed the buffer. This is a defensive fix for a memory-safety bug in the hardware-wallet communication path.
Changed components
src/device/device_io_hid.cppMonero hardware wallet HID I/OInspect captured patch +1 / −0
diff --git a/src/device/device_io_hid.cpp b/src/device/device_io_hid.cpp
index db3a445..e4c236e 100644
--- a/src/device/device_io_hid.cpp
+++ b/src/device/device_io_hid.cpp
@@ -219,6 +219,7 @@ namespace hw {
if (result != 0) {
break;
}
+ ASSERT_X(offset + MAX_BLOCK <= sizeof(buffer), "HID response too large for buffer");
hid_ret = hid_read_timeout(this->usb_device, buffer + offset, MAX_BLOCK, this->timeout);
ASSERT_X(hid_ret>=0, "Unable to receive hidapi response. Error "+std::to_string(result)+": "+ safe_hid_error(this->usb_device));
result = (unsigned int)hid_ret;
Why this scored 58/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.