From 967424cb79af04d321da557d071c514f214ec279 Mon Sep 17 00:00:00 2001 From: zwx Date: Fri, 10 Apr 2026 15:18:29 +0800 Subject: [PATCH 1/4] feat(openthread): update openthread upstream --- components/openthread/openthread | 2 +- components/openthread/sbom_openthread.yml | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/components/openthread/openthread b/components/openthread/openthread index b1a37932b18..a98813b30ae 160000 --- a/components/openthread/openthread +++ b/components/openthread/openthread @@ -1 +1 @@ -Subproject commit b1a37932b1830518f6fa6c92dfb4123a01ac3052 +Subproject commit a98813b30ae58f9a95ece680b9cc46c3874de6ea diff --git a/components/openthread/sbom_openthread.yml b/components/openthread/sbom_openthread.yml index 29346f14305..ea5d2d11e7c 100644 --- a/components/openthread/sbom_openthread.yml +++ b/components/openthread/sbom_openthread.yml @@ -5,4 +5,4 @@ supplier: 'Organization: Espressif Systems (Shanghai) CO LTD' originator: 'Organization: Google LLC' description: OpenThread released by Google is an open-source implementation of the Thread networking url: https://github.com/espressif/openthread -hash: b1a37932b1830518f6fa6c92dfb4123a01ac3052 +hash: a98813b30ae58f9a95ece680b9cc46c3874de6ea From aba72186cea638527aed72e53d29867f11fdf64b Mon Sep 17 00:00:00 2001 From: Zhang Wen Xu Date: Tue, 14 Apr 2026 03:27:44 +0000 Subject: [PATCH 2/4] feat(openthread/openthread/lib): update thread-lib for upstream a98813b30 * esp-openthread: thread_zigbee/esp-openthread@654e8d3b2 * openthread: espressif/openthread@a98813b30 * esp-idf: espressif/esp-idf@967424cb7 --- components/openthread/lib | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/components/openthread/lib b/components/openthread/lib index 07360e69add..af39c351ae9 160000 --- a/components/openthread/lib +++ b/components/openthread/lib @@ -1 +1 @@ -Subproject commit 07360e69adde66c29d62aa4f165029b133c3cc07 +Subproject commit af39c351ae923cb4b8c7946fd969532954e4ae66 From e8bcdf4e4de59d40ddece355b4bb2bcb7e8f5bdd Mon Sep 17 00:00:00 2001 From: zwx Date: Tue, 14 Apr 2026 17:13:59 +0800 Subject: [PATCH 3/4] fix(openthread): fix build failure in spinel-only mode --- .../openthread-core-esp32x-spinel-config.h | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/components/openthread/private_include/openthread-core-esp32x-spinel-config.h b/components/openthread/private_include/openthread-core-esp32x-spinel-config.h index 7c3853ecb56..9e01fb818af 100644 --- a/components/openthread/private_include/openthread-core-esp32x-spinel-config.h +++ b/components/openthread/private_include/openthread-core-esp32x-spinel-config.h @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2021-2025 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2021-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -76,3 +76,15 @@ #ifndef OPENTHREAD_SPINEL_CONFIG_COPROCESSOR_RESET_FAILURE_CALLBACK_ENABLE #define OPENTHREAD_SPINEL_CONFIG_COPROCESSOR_RESET_FAILURE_CALLBACK_ENABLE 1 #endif + +/** + * @def OPENTHREAD_CONFIG_MULTIPLE_INSTANCE_ENABLE + * + * In spinel-only mode no Instance object is compiled or instantiated, so the + * single-instance path (Instance::Get().GetLogLevel()) is unavailable. Enabling + * multiple-instance support forces the logging APIs to use the global log level + * (Instance::GetGlobalLogLevel()), which does not depend on an Instance object. + */ +#ifndef OPENTHREAD_CONFIG_MULTIPLE_INSTANCE_ENABLE +#define OPENTHREAD_CONFIG_MULTIPLE_INSTANCE_ENABLE 1 +#endif From a3f3685506d9c2ee2ceca2e1a8cf2b4ca34dfb84 Mon Sep 17 00:00:00 2001 From: Mahavir Jain Date: Fri, 15 May 2026 09:48:56 +0530 Subject: [PATCH 4/4] fix(openthread): exclude CVE-2026-8369 from the list --- components/openthread/sbom_openthread.yml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/components/openthread/sbom_openthread.yml b/components/openthread/sbom_openthread.yml index ea5d2d11e7c..9d7a43b78f7 100644 --- a/components/openthread/sbom_openthread.yml +++ b/components/openthread/sbom_openthread.yml @@ -1,8 +1,11 @@ name: 'openthread' -version: '2023-07-06' +version: '2025-06-12' cpe: cpe:2.3:o:google:openthread:{}:*:*:*:*:*:*:* supplier: 'Organization: Espressif Systems (Shanghai) CO LTD' originator: 'Organization: Google LLC' description: OpenThread released by Google is an open-source implementation of the Thread networking url: https://github.com/espressif/openthread hash: a98813b30ae58f9a95ece680b9cc46c3874de6ea +cve-exclude-list: + - cve: CVE-2026-8369 + reason: We use Espressif’s NAT64 implementation and hence this CVE from the upstream NAT64 implementation is not applicable.