AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Low 33 Bitcoin

Merge rust-bitcoin/rust-bitcoin#6946: Fix integer overflow in `get_array`

Public commit record

What the developer wrote

Authored by Andrew Poelstra

100/100 · Strong
Merge rust-bitcoin/rust-bitcoin#6946: Fix integer overflow in `get_array`

56fb1287d8f590f1a739b5b23f0d621efa89dc33 Fix integer overflow in `get_array` (Martin Habovstiak)

Pull request description:

The `get_array` method promised to return `None` in case of out-of-bounds access but internally tried to add caller-controlled values which would result in integer overflow. In case overflow happens the attempted read is certainly out of bounds - goes beyond address space. Therefore this commit treats it as such and fixes it to return `None`.

**This bug was found by creusot.** :tada: :tada: :tada:

Though now that I think about it, it would only cause crashes with debug assertions but ironically, without them it would work fine because the garbage `end` value would make the range invalid causing `get` to return `None.` Still, I believe this fix is better than changing it to `wrapping_add` because it's less confusing for both humans and creusot and there's a good chance the compiler will optimize-out the check.


ACKs for top commit:
apoelstra:
ACK 56fb1287d8f590f1a739b5b23f0d621efa89dc33; successfully ran local tests
tcharding:
ACK 56fb1287d8f590f1a739b5b23f0d621efa89dc33


Tree-SHA512: 970ed2cbbf7a8510854a307ba85929221fefb8b18fe34beed560e116cbe9d111b14150579ee329fdcb97ef0f2da1b8da6bc58e45133f2b1573fa9d7d2f8bd177
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit fixes a small but real bug in a Rust helper that reads fixed-size chunks from a data slice. The helper was supposed to safely return 'nothing' when asked to read past the end of the data, but it accidentally added two numbers together in a way that could overflow. In Rust, that overflow can crash a program in debug builds. In release builds it would not crash, but the code was still doing the wrong thing logically. The fix uses safe arithmetic so the overflow is caught and the helper returns 'nothing' as documented.

Recommended action

No urgent action required beyond applying the patch. Users running debug builds of code that passes untrusted offsets to `get_array` could experience panics; upgrading removes that risk. Review other slice helpers for similar unchecked arithmetic.

Security signals we found

01

Integer overflow in bounds-checking helper

02

Contract violation: method documented to return None on out-of-bounds access could panic instead

03

Debug-build panic (denial of service) possible

04

Found by formal verification tool (creusot)

Risk score

Why this scored 33/100

Our methodology →
Potential impact 8/30
Exploitability 4/25
Stealth signal 3/15
Affected reach 6/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.