AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
High 79 Bitcoin

Merge rust-bitcoin/rust-bitcoin#6920: primitives: Bound aggregate size and weight while decoding

Public commit record

What the developer wrote

Authored by Andrew Poelstra

91/100 · Strong
Merge rust-bitcoin/rust-bitcoin#6920: primitives: Bound aggregate size and weight while decoding

f08650da5a538330445471b0c297145579b26164 primitives: Test over-weight Block rejected (Jamil Lambert, PhD)
ed3c6ba1578e21ca40b7662efdbf34f3666d67cc primitives: Reject over-weight Block (Jamil Lambert, PhD)
9880a744f461c3054e0a6cbf9d9181350c9171e3 primitives: Test over-weight Transaction rejected (Jamil Lambert, PhD)
dd6dbfbc905f757e4065c81726d4e234d28146a6 primitives: Reject over-weight Transaction (Jamil Lambert, PhD)
b59fbee3b753f1dfc3f02190db11960b530de859 primitives: Test over size limit Witness rejected (Jamil Lambert, PhD)
cd4818dd8bc24166b362a2f9191c7e48d5e95814 primitives: Reject over size limit Witness (Jamil Lambert, PhD)

Pull request description:

The streaming `WitnessDecoder`, `TransactionDecoder` and `BlockDecoder` each bound their individual fields but never the aggregate they retain, so an untrusted reader can be fed many individually legal fields that together far exceed any valid Bitcoin object and exhaust memory.

Reject a `Witness` whose combined serialized element size exceeds the 4 MB block-weight bound, and reject a `Transaction` or `Block` whose `Weight` exceeds the maximum block weight. Add regression tests for each.

Closes project-loupe/audit-rust-bitcoin#85
Closes project-loupe/audit-rust-bitcoin#188
Closes project-loupe/audit-rust-bitcoin#199


ACKs for top commit:
apoelstra:
ACK f08650da5a538330445471b0c297145579b26164; successfully ran local tests
tcharding:
ACK f08650da5a538330445471b0c297145579b26164


Tree-SHA512: 0143010d52692f4eeb221b732943a9295ce037f6d0071339d22a58f7b1c39061549e5a5e6ec7e6d487586e6c2cdc1d24ba3bb4422dab9e2bbed8c06f65b3b184
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This update fixes a memory-exhaustion risk in the rust-bitcoin library's streaming decoders for Bitcoin blocks, transactions, and witness data. Previously, an attacker could send many individually legal pieces of data that, when added together, created an impossibly large Bitcoin object, causing the receiving program to use excessive memory and possibly crash. The patch now rejects blocks, transactions, and witness stacks whose total size or weight exceeds Bitcoin's 4 MB block-weight limit during decoding, before all the data is fully loaded into memory. It also adds tests proving the new limits work.

Recommended action

Upgrade to a rust-bitcoin version containing this merge commit. If you run code that decodes blocks, transactions, or witness data from untrusted sources (e.g., P2P network messages, RPC responses, block files), ensure you are on the patched version. No application-level workaround is practical because the vulnerability is in the decoder itself.

Security signals we found

01

CWE-770: Allocation of Resources Without Limits or Throttling

02

CWE-400: Uncontrolled Resource Consumption

03

Denial-of-Service via malicious deserialization input

04

Streaming decoder aggregate-bound enforcement

05

Memory-exhaustion prevention for untrusted network data

Risk score

Why this scored 79/100

Our methodology →
Potential impact 22/30
Exploitability 18/25
Stealth signal 12/15
Affected reach 13/15
Confidence 9/10
Evidence quality 5/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.