From 23bd88f3924fbf1020d0133fd89505549d7739da Mon Sep 17 00:00:00 2001 From: Aditya Patwardhan Date: Mon, 29 Jun 2026 13:49:05 +0530 Subject: [PATCH] fix(protocomm): guard NULL pc->sec in protocomm_get_sec_version protocomm_get_sec_version() validated pc, sec_ver and sec_patch_ver but dereferenced pc->sec unconditionally. pc->sec remains NULL until protocomm_set_security() runs, so calling this API before security is configured dereferences a NULL pointer and crashes (HW-confirmed LoadProhibited on ESP32-S3, EXCVADDR=0). Return ESP_ERR_INVALID_STATE when pc->sec is NULL. Closes SEC-581 --- components/protocomm/src/common/protocomm.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/components/protocomm/src/common/protocomm.c b/components/protocomm/src/common/protocomm.c index 1a548267904..824d59f0a7f 100644 --- a/components/protocomm/src/common/protocomm.c +++ b/components/protocomm/src/common/protocomm.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2018-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2018-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -433,6 +433,10 @@ esp_err_t protocomm_get_sec_version(protocomm_t *pc, int *sec_ver, uint8_t *sec_ return ESP_ERR_INVALID_ARG; } + if (pc->sec == NULL) { + return ESP_ERR_INVALID_STATE; + } + *sec_ver = pc->sec->ver; *sec_patch_ver = pc->sec->patch_ver;