AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 59 Cryptographic libraries

wallet: prevent close from freeing wallet during in-flight calls

Public commit record

What the developer wrote

Authored by woodser

73/100 · Adequate
wallet: prevent close from freeing wallet during in-flight calls

Native calls hold a shared read lock; close() aborts sync and takes
the write lock (bounded 30s) before freeing the wallet in c++.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context
The short version

What changed, and why it matters

This commit fixes a race condition in a Monero wallet Java library. Previously, calling close() on a wallet could free the underlying native wallet memory while other operations were still running, which could cause crashes or unpredictable behavior. The fix wraps every wallet operation in a shared read lock and makes close() acquire a write lock (waiting up to 30 seconds) before freeing the wallet, so close() cannot happen mid-operation.

Recommended action

Review the C++ side to ensure closeJni() is safe to call after the write lock is acquired and that no native callbacks occur after close begins. Consider whether the 30-second timeout is appropriate for long-running operations like sync or sweep. Verify that beginCall()/endCall() pairs are consistently applied to any newly added methods and that no deadlocks can occur with synchronized methods or listener callbacks.

Security signals we found

01

Race condition between wallet close() and in-flight native calls

02

Potential use-after-free of C++ wallet handle (jniWalletHandle)

03

New read/write locking around all JNI wallet operations

04

close() now waits bounded time for in-flight calls before freeing native wallet

05

isClosed made volatile for safe publication across threads

Risk score

Why this scored 59/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 7/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.