fix(protocomm): guard NULL pc->sec in protocomm_get_sec_version

protocomm_get_sec_version() validated pc, sec_ver and sec_patch_ver but
dereferenced pc->sec unconditionally. pc->sec remains NULL until
protocomm_set_security() runs, so calling this API before security is
configured dereferences a NULL pointer and crashes (HW-confirmed
LoadProhibited on ESP32-S3, EXCVADDR=0). Return ESP_ERR_INVALID_STATE
when pc->sec is NULL.

Closes SEC-581
This commit is contained in:
Aditya Patwardhan
2026-09-21 11:41:57 +05:30
parent 8b1ad80381
commit 23bd88f392
+5 -1
View File
@@ -1,5 +1,5 @@
/*
* SPDX-FileCopyrightText: 2018-2025 Espressif Systems (Shanghai) CO LTD
* SPDX-FileCopyrightText: 2018-2026 Espressif Systems (Shanghai) CO LTD
*
* SPDX-License-Identifier: Apache-2.0
*/
@@ -433,6 +433,10 @@ esp_err_t protocomm_get_sec_version(protocomm_t *pc, int *sec_ver, uint8_t *sec_
return ESP_ERR_INVALID_ARG;
}
if (pc->sec == NULL) {
return ESP_ERR_INVALID_STATE;
}
*sec_ver = pc->sec->ver;
*sec_patch_ver = pc->sec->patch_ver;