diff --git a/excluded_cves.yaml b/excluded_cves.yaml new file mode 100644 index 00000000000..b72ba4e3b2f --- /dev/null +++ b/excluded_cves.yaml @@ -0,0 +1,54 @@ +# SPDX-FileCopyrightText: 2026 Espressif Systems (Shanghai) CO LTD +# SPDX-License-Identifier: Apache-2.0 +# +# Repository-local CVE exclusions for this ESP-IDF revision. +# +# esp-idf-sbom merges this file into its global exclusion list when scanning +# this tree (see the "Excluding CVEs" section of the esp-idf-sbom README). It +# uses the same format as esp-idf-sbom's own excluded_cves.yaml. Because the +# file lives in the tree it is scoped to this branch/revision: the affected +# release tag (v5.3.5) predates it and is still reported, while release/v5.3 -- +# which carries the fixes and reports 5.3.5 until 5.3.6 is released -- is not. +# +# Every CVE below is pinned by NVD to 5.3.5 on the 5.3 line and patched in +# 5.3.6; the fixes are already merged on release/v5.3 (fix commit cited in each +# reason). Once version.cmake is bumped to 5.3.6, NVD no longer matches and +# these entries become no-ops that can be removed. + +CVE-2026-45160: + cpes: + - cpe: cpe:2.3:a:espressif:esp-idf:5.3.5:*:*:*:*:*:*:* + reason: >- + Out-of-bounds read in the DHCP server option parser + (components/lwip/apps/dhcpserver/dhcpserver.c). Fixed on release/v5.3, + patched in 5.3.6 (commit 9f713dbc9498). The branch still reports 5.3.5 + until 5.3.6 is released. + +CVE-2026-45541: + cpes: + - cpe: cpe:2.3:a:espressif:esp-idf:5.3.5:*:*:*:*:*:*:* + reason: >- + NULL-pointer dereference in the esp_http_server WebSocket + subprotocol-negotiation path (components/esp_http_server/src/httpd_ws.c). + Fixed on release/v5.3, patched in 5.3.6 (commit f88a47e4f37f). The branch + still reports 5.3.5 until 5.3.6 is released. + +CVE-2026-45542: + cpes: + - cpe: cpe:2.3:a:espressif:esp-idf:5.3.5:*:*:*:*:*:*:* + reason: >- + Heap buffer overflow in the protocomm SRP6a session setup + (handle_session_command0() in + components/protocomm/src/security/security2.c) from an unbounded username + length copy. Fixed on release/v5.3, patched in 5.3.6 (commit 0ea58d79845a). + The branch still reports 5.3.5 until 5.3.6 is released. + +CVE-2026-46532: + cpes: + - cpe: cpe:2.3:a:espressif:esp-idf:5.3.5:*:*:*:*:*:*:* + reason: >- + Out-of-bounds read in the BlueDroid AVRCP vendor-command parser + (avrc_pars_vendor_cmd() in + components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c). Fixed on + release/v5.3, patched in 5.3.6 (commit 7c004d3fe302). The branch still + reports 5.3.5 until 5.3.6 is released.