Coin Brief ENDE

Monero 0.18.5.3 hardens restricted RPC nodes and wallets against malicious remote nodes

The Monero project released version 0.18.5.3, "Fluorine Fermi", on 6 October and calls it a highly recommended release with a large number of bug fixes. It is the work of 17 people, 182 commits and 4,162 new lines of code, according to the announcement.

For node operators.

  • Public IPv6 connection limits are now grouped by /64, so one network block counts as one source.
  • Restricted RPC, the mode used by public nodes, gets several privacy changes: get_transaction_pool is disabled, privacy filtering is improved, get_public_nodes returns only public-zone peers, deep block submissions are rejected, and ZMQ hides request contents from logs.
  • Rejected block spans from disconnected peers are flushed; handshake and timeout handling, LMDB resizing, and transaction serialization and validation are improved.
Monero 0.18.5.3 hardens restricted RPC nodes and wallets against malicious remote nodes
Monero 0.18.5.3 hardens restricted RPC nodes and wallets against malicious remote nodes — Coin Brief

For wallets.

  • Hardening against malicious remote nodes, in four separate changes.
  • Better transaction validation for cold and multisig signing; all copies of multisig nonces are now erased together; fixes for multisig output import and refresh.
  • Key image domains are validated in reserve proofs, and an infinite loop when estimating transactions with many outputs is fixed.
  • The wallet RPC adds transaction weight to describe_transfer.

Also: protection against log injection from malformed JSON and HTTP headers, a size check on Trezor bridge responses, and fixed HTTP connection reuse after remote disconnects.

Binaries are on the project's downloads page with SHA256 hashes published in the announcement; the full change list is on GitHub. A GUI release with the same version number was announced the same day.

Written by Victoria Shinder.