fix(nspv/wallet): bound nSPV request buffers + fix uninitialized fee / null-deref
hush_nSPV_fullnode.h: bound the REMOTERPC method strcpy and json memcpy to their fixed buffers (method[64], json[11000]); add lower-length and memcpy-source bounds to the UTXOS/TXIDS coinaddr[64] copies and the MEMPOOL handler. These paths deserialize attacker-controlled request bytes -> stack overflow / OOB read. The nSPV server is opt-in via -nspv_msg (off by default; DragonX uses lightwalletd). rpc/blockchain.cpp: getchaintxstats null-checks pwalletMain (crash under -disablewallet). wallet/rpcwallet.cpp: z_sendmany initializes nFee to the default miners fee (was read uninitialized when no fee param supplied). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -5146,7 +5146,7 @@ UniValue z_sendmany(const UniValue& params, bool fHelp, const CPubKey& mypk)
|
||||
}
|
||||
|
||||
//GOAL: choose one random zaddress with enough funds
|
||||
CAmount nFee;
|
||||
CAmount nFee = ASYNC_RPC_OPERATION_DEFAULT_MINERS_FEE; // default when params.size()<=3 (was uninitialized)
|
||||
if (params.size() > 3) {
|
||||
if (params[3].get_real() == 0.0) {
|
||||
nFee = 0;
|
||||
|
||||
Reference in New Issue
Block a user