Merge branch 'bugfix/fix_protocomm_sec2_double_free_decrypt_v6.0' into 'release/v6.0'

fix(protocomm): null output buffer pointer on crypto failure (v6.0)

See merge request espressif/esp-idf!49701
This commit is contained in:
Mahavir Jain
2026-06-29 11:20:32 +05:30
2 changed files with 5 additions and 0 deletions
@@ -555,6 +555,7 @@ static esp_err_t sec1_crypt(protocomm_security_handle_t handle,
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "psa_cipher_update failed with status=%d", status);
free(*outbuf);
*outbuf = NULL;
return ESP_FAIL;
}
return ESP_OK;
@@ -505,12 +505,14 @@ static esp_err_t sec2_encrypt(protocomm_security_handle_t handle,
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "psa_aead_encrypt failed with status=%d", status);
free(*outbuf);
*outbuf = NULL;
return ESP_FAIL;
}
if (out_len != *outlen) {
ESP_LOGE(TAG, "psa_aead_encrypt output length mismatch: expected %zd, got %zu", *outlen, out_len);
free(*outbuf);
*outbuf = NULL;
return ESP_FAIL;
}
@@ -566,12 +568,14 @@ static esp_err_t sec2_decrypt(protocomm_security_handle_t handle,
if (status != PSA_SUCCESS) {
ESP_LOGE(TAG, "psa_aead_decrypt failed with status=%d", status);
free(*outbuf);
*outbuf = NULL;
return ESP_FAIL;
}
if (out_len != *outlen) {
ESP_LOGE(TAG, "psa_aead_decrypt output length mismatch: expected %zd, got %zu", *outlen, out_len);
free(*outbuf);
*outbuf = NULL;
return ESP_FAIL;
}