AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
High 71 Bitcoin

Merge rust-bitcoin/rust-bitcoin#6915: primitives: Fix `Witness` handling of oversized items

Public commit record

What the developer wrote

Authored by Andrew Poelstra

91/100 · Strong
Merge rust-bitcoin/rust-bitcoin#6915: primitives: Fix `Witness` handling of oversized items

8caa5f364f2e31894090eb6911a6e796c7519784 primitives: Test coinbase witness count validated (Jamil Lambert, PhD)
b8b78386dc47d434ca24e650007846362ad746b7 primitives: Check coinbase witness count (Jamil Lambert, PhD)
e6068218a02f9ae469d2881eb431be1f6ae45de9 primitives: Test wtxid with oversized elements (Jamil Lambert, PhD)
fa8c510647aa3ae0c9f8a9acfc4f0df3df7f86c2 primitives: Hash the full witness encoding (Jamil Lambert, PhD)
822d6e01fbbf502d9867a20b0bafed180163106d primitives: Test oversized Witness equality (Jamil Lambert, PhD)
2b2fea885c73ef35757b847d67fafeeed3be7e39 primitives: Fix oversized Witness slice equality (Jamil Lambert, PhD)
4a5855bce5ee5fcbe0ab3d89323dd699d81b911b primitives: Test Witness::size for oversized item (Jamil Lambert, PhD)
c529e02377930cad43c980a33258052983b3da6e primitives: Fix Witness::size oversized item (Jamil Lambert, PhD)

Pull request description:

`Witness::iter` stops before an item larger than it will decode, but `Witness::len` still counts it. Consumers that trusted the iterator then mishandled a `Witness` holding such an item: `size` undercounted its bytes, slice equality reported it equal to a different one-element stack, and the `wtxid` dropped it. The coinbase commitment check also collected the whole `Witness` before testing its length.

Compute `size` from the stored serialized length, compare witnesses through their iterators, hash the full `Witness` encoding into the `wtxid`, and check the coinbase witness length before reading it.

Closes project-loupe/audit-rust-bitcoin#58
Closes project-loupe/audit-rust-bitcoin#70
Closes project-loupe/audit-rust-bitcoin#185
Closes project-loupe/audit-rust-bitcoin#69
Closes project-loupe/audit-rust-bitcoin#184


ACKs for top commit:
apoelstra:
ACK 8caa5f364f2e31894090eb6911a6e796c7519784; successfully ran local tests
tcharding:
ACK 8caa5f364f2e31894090eb6911a6e796c7519784
satsfy:
tACK 8caa5f364f2e31894090eb6911a6e796c7519784


Tree-SHA512: 77aaeff42eac53b37df8b8d55085d1e6a73552dcf07a9c05dfd564ed6bbc144185a904839037f0dd54f8b9231fca69155ff80d0f6d837bf039c05a7183abf732
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Mentions testing or verification✓ Links an issue, advisory, or supporting reference
The short version

What changed, and why it matters

This commit fixes a bug in how the Rust Bitcoin library counts and compares transaction witness data when a witness contains an oversized item. Previously, several functions relied on an iterator that silently skips oversized items, causing the reported size to be too small, equality checks to wrongly treat different witnesses as equal, and transaction witness IDs (wtxid) to ignore the oversized data. The patch makes these operations use the full stored witness encoding instead. It also fixes a coinbase block validation check so it rejects multi-item coinbase witnesses in constant time rather than collecting and possibly truncating them.

Recommended action

Review and merge this fix; then audit any downstream code that calls `Witness::iter` and assumes it yields all stored elements, especially in validation, signing, or serialization paths. Consider adding documentation that `iter` is capped and that `size`, equality, and hashing must use the full encoding.

Security signals we found

01

Inconsistent serialization/iterator behavior for oversized witness items

02

wtxid collision risk between transactions differing only in oversized witness bytes

03

Incorrect witness equality for oversized single-item stacks

04

Undercounted witness size could affect fee estimation or size-limited validation

05

Coinbase witness-commitment validation accepted truncated/oversized multi-item witnesses

06

Fixes explicitly close multiple audit tracker issues (project-loupe/audit-rust-bitcoin#58, #69, #70, #184, #185)

Risk score

Why this scored 71/100

Our methodology →
Potential impact 22/30
Exploitability 14/25
Stealth signal 11/15
Affected reach 12/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.