AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 62 Bitcoin

Fix integer overflow in `get_array`

Public commit record

What the developer wrote

Authored by Martin Habovstiak

73/100 · Adequate
Fix integer overflow in `get_array`

The `get_array` method promised to return `None` in case of
out-of-bounds access but internally tried to add caller-controlled
values which would result in integer overflow. In case overflow happens
the attempted read is certainly out of bounds - goes beyond address
space. Therefore this commit treats it as such and fixes it to return
`None`.

This bug was found by creusot.
✓ Descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit fixes a bug in a Rust helper method called `get_array`, which is meant to safely read a fixed-size chunk from a slice and return nothing if the requested range is out of bounds. The bug was that the code added the caller's offset and length together using normal integer addition, which can overflow on large values. In Rust, integer overflow in release builds is defined to wrap around, so a huge offset plus length could produce a small number, making the out-of-bounds check pass incorrectly. The fix uses checked addition so that any overflow is treated as an out-of-bounds request and returns nothing, as the method's contract promises.

Recommended action

Review all call sites of `get_array` to confirm none relied on the previous overflow behavior, and audit other slice-indexing helpers in the crate for similar unchecked offset/length arithmetic. Consider adding unit tests with `usize::MAX` offsets to prevent regression.

Security signals we found

01

Integer overflow in bounds calculation

02

Potential panic due to violated internal length expectation

03

Caller-controlled arithmetic used for memory access bounds

04

Fix uses checked_add to enforce documented out-of-bounds contract

Risk score

Why this scored 62/100

Our methodology →
Potential impact 18/30
Exploitability 12/25
Stealth signal 8/15
Affected reach 10/15
Confidence 9/10
Evidence quality 5/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.