fix: output note index out of bounds in asset and attachment API#2792
Merged
PhilippGackstatter merged 2 commits intotx-kernel-audit-fixesfrom Apr 20, 2026
Merged
Conversation
6e5f7af to
907a8d5
Compare
dfe755c to
1742373
Compare
907a8d5 to
da4540c
Compare
PhilippGackstatter
added a commit
that referenced
this pull request
Apr 24, 2026
* fix: output note index bound assertion in add_asset/attachment * chore: add regression test for output note index OOB
PhilippGackstatter
added a commit
that referenced
this pull request
Apr 24, 2026
* fix: output note index bound assertion in add_asset/attachment * chore: add regression test for output note index OOB
bobbinth
pushed a commit
to huitseeker/miden-base
that referenced
this pull request
Apr 26, 2026
…iden#2824) * fix: output note index out of bounds in asset and attachment API (0xMiden#2792) * fix: output note index bound assertion in add_asset/attachment * chore: add regression test for output note index OOB * chore: add changelog
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes output note index out of bounds in asset and attachment API by using
output_note::assert_note_index_in_boundsconsistently for all output_note APIs inapi.masm.Note that there were cargo deny errors in this PR's CI and ignores were added on the base branch directly in 1742373, since these issues are unimportant for the audit and have been addressed on next. That way, we can cherry-pick this PR's merge commit back into next without accidentally ignoring these advisories.
closes #2763