=== CRITICAL BUGS IN NERDMINER V2 ===
-
ESP32 FREEZE ON SHARE FOUND (Bugs F1 & F2)
- Affected File: utils.cpp (within "checkValid()")
- Issue A: The function uses 'memcpy(diff_target, &target, 32)', which copies the address
of the pointer instead of the actual data, loading memory garbage.
- Issue B: The loop 'for(uint8_t i=31; i>=0; i--)' uses an unsigned integer (uint8_t)
which cannot be negative. Decrementing past 0 wraps it to 255, creating an
infinite loop that immediately freezes the ESP32.
-
CORRUPTED TARGET COMPARISON (Bug BUG-3)
- Affected File: utils.cpp (within "calculateMiningData()")
- Issue: The function calls 'to_byte_array(target, 32, mMiner.bytearray_target)'. The size
argument should be 64 (for 64 hex characters) instead of 32.
- Impact: Only the first 16 bytes of the 32-byte target are written, leaving the rest
uninitialized. Valid blocks/shares cannot be correctly validated.
-
STACK OVERFLOW VULNERABILITY (Bug BUG-2)
- Affected File: utils.cpp (within "calculateMiningData()")
- Issue: The calculation of the target buffer offset ('zeros - 2') derived from pool 'nbits'
lacks boundary verification.
- Impact: A custom or malicious pool sending very low difficulty exponents causes a negative
offset, triggering out-of-bounds stack corruption and crashing the ESP32.
=== CRITICAL BUGS IN NERDMINER V2 ===
ESP32 FREEZE ON SHARE FOUND (Bugs F1 & F2)
of the pointer instead of the actual data, loading memory garbage.
which cannot be negative. Decrementing past 0 wraps it to 255, creating an
infinite loop that immediately freezes the ESP32.
CORRUPTED TARGET COMPARISON (Bug BUG-3)
argument should be 64 (for 64 hex characters) instead of 32.
uninitialized. Valid blocks/shares cannot be correctly validated.
STACK OVERFLOW VULNERABILITY (Bug BUG-2)
lacks boundary verification.
offset, triggering out-of-bounds stack corruption and crashing the ESP32.