From 36bb2d0e7d401876557a42ecf5f2cac4bbd36f20 Mon Sep 17 00:00:00 2001 From: Thomas Date: Sat, 20 Jun 2026 21:04:51 +0200 Subject: [PATCH] wallet2: avoid std::out_of_range on a truncated tx set blob parse_unsigned_tx_from_str() and parse_tx_from_str() strip the magic, then read the version byte and call s.substr(1) without checking a version byte follows. A blob equal to just the magic leaves an empty remainder, so s.substr(1) throws std::out_of_range instead of the function returning false. Require magic + a version byte first. --- src/wallet/wallet2.cpp | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/wallet/wallet2.cpp b/src/wallet/wallet2.cpp index 3bd03e6ed..208969cef 100644 --- a/src/wallet/wallet2.cpp +++ b/src/wallet/wallet2.cpp @@ -7743,7 +7743,7 @@ bool wallet2::parse_unsigned_tx_from_str(const std::string &unsigned_tx_st, unsi { std::string s = unsigned_tx_st; const size_t magiclen = strlen(UNSIGNED_TX_PREFIX) - 1; - if (strncmp(s.c_str(), UNSIGNED_TX_PREFIX, magiclen)) + if (s.size() < magiclen + 1 || strncmp(s.c_str(), UNSIGNED_TX_PREFIX, magiclen)) { LOG_PRINT_L0("Bad magic from unsigned tx"); return false; @@ -8021,7 +8021,7 @@ bool wallet2::parse_tx_from_str(const std::string &signed_tx_st, std::vector