Skip to content

Critical Bugs #797

Description

@oli737

=== CRITICAL BUGS IN NERDMINER V2 ===

  1. ESP32 FREEZE ON SHARE FOUND (Bugs F1 & F2)

    • Affected File: utils.cpp (within "checkValid()")
    • Issue A: The function uses 'memcpy(diff_target, &target, 32)', which copies the address
      of the pointer instead of the actual data, loading memory garbage.
    • Issue B: The loop 'for(uint8_t i=31; i>=0; i--)' uses an unsigned integer (uint8_t)
      which cannot be negative. Decrementing past 0 wraps it to 255, creating an
      infinite loop that immediately freezes the ESP32.
  2. CORRUPTED TARGET COMPARISON (Bug BUG-3)

    • Affected File: utils.cpp (within "calculateMiningData()")
    • Issue: The function calls 'to_byte_array(target, 32, mMiner.bytearray_target)'. The size
      argument should be 64 (for 64 hex characters) instead of 32.
    • Impact: Only the first 16 bytes of the 32-byte target are written, leaving the rest
      uninitialized. Valid blocks/shares cannot be correctly validated.
  3. STACK OVERFLOW VULNERABILITY (Bug BUG-2)

    • Affected File: utils.cpp (within "calculateMiningData()")
    • Issue: The calculation of the target buffer offset ('zeros - 2') derived from pool 'nbits'
      lacks boundary verification.
    • Impact: A custom or malicious pool sending very low difficulty exponents causes a negative
      offset, triggering out-of-bounds stack corruption and crashing the ESP32.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions