Skip to content

increase_allowance can overflow when adding to existing allowance #501

Description

@DeFiVC

What

increase_allowance (learn-token lib.rs:1274) computes new_amount = current + additional_amount at line 1292 using plain i128 addition without overflow protection. If current + additional_amount > i128::MAX, the addition will panic (Soroban has overflow-checks enabled in release profile).

While the panic prevents actual overflow, the error is an uncontrolled host panic rather than a graceful ContractError return. More importantly, there is no upper-bound check on the resulting allowance -- a user could set an astronomically large allowance that, while not overflowing, is far beyond any reasonable token supply.

Note: #434 was previously filed and closed for this issue, but the code at line 1292 still uses plain +.

Why

Allowance overflow could be used in a griefing attack: set an allowance near i128::MAX, then call increase_allowance with any positive value to trigger a host panic. The error message would be opaque to the caller.

Scope

Use checked_add and return a typed error:

let new_amount = current.checked_add(additional_amount)
    .ok_or(ContractError::MaxSupplyExceeded)?;

Or add a reasonable upper bound (e.g., max_supply).

Acceptance Criteria

  • increase_allowance with values that would overflow returns a typed error instead of host panic
  • Test verifies the overflow case

Technical Context

  • contracts/learn-token/src/lib.rs:1274-1297 -- increase_allowance
  • contracts/learn-token/src/lib.rs:1292 -- let new_amount = current + additional_amount

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Stellar WaveIssues in the Stellar wave programbugSomething isn't workingmediumFunctionality impaired but workaround exists, edge case, partial featurerustRust languagesecuritySecurity concern

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions