Skip to content

bech32: fix encoding a maximum length segwit address - #545

Closed
brunoerg wants to merge 1 commit into
ElementsProject:masterfrom
brunoerg:fix-segwit-addr-encode-overflow
Closed

brunoerg wants to merge 1 commit into
ElementsProject:masterfrom
brunoerg:fix-segwit-addr-encode-overflow

Conversation

@brunoerg

@brunoerg brunoerg commented Sep 2, 2026

Copy link
Copy Markdown
Contributor

bech32_encode() allows an encoded address of up to 90 characters, as BIP-173 specifies, but wally_addr_segwit_from_bytes() encodes into a 90 byte stack buffer. When the address is exactly 90 characters long the NUL terminator is written one byte past the end of the buffer.

Any 30 character hrp with a 32 byte version 0 program hits the boundary, as does any other combination whose encoded length is 90.

Size the buffer for the maximum length plus the terminator, matching what the blech32 encoder already does, and add the boundary case to the bech32 test vectors so it is exercised in both directions.

bech32_encode() allows an encoded address of up to 90 characters, as
BIP-173 specifies, but wally_addr_segwit_from_bytes() encodes into a
90 byte stack buffer. When the address is exactly 90 characters long the
NUL terminator is written one byte past the end of the buffer.

Any 30 character hrp with a 32 byte version 0 program hits the boundary,
as does any other combination whose encoded length is 90.

Size the buffer for the maximum length plus the terminator, matching
what the blech32 encoder already does, and add the boundary case to the
bech32 test vectors so it is exercised in both directions.

Found by bitcoinfuzz.
@jgriffiths jgriffiths mentioned this pull request Sep 3, 2026
@jgriffiths

Copy link
Copy Markdown
Contributor

Hi @brunoerg Merged with rebase/changelog item removed (as that's for the previous release and will be updated before the next release). Many thanks!

@jgriffiths jgriffiths closed this Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants