Commit Graph
53404 Commits
Author SHA1 Message Date
Ashish Sharma 8d8068aee3 fix(esp_tee): fix DS-lock leak, intr-matrix OOB, calloc overflow, attestation leak 2026-07-13 14:40:44 +08:00
Ashish Sharma 2a63a05a85 fix(esp-tls): reject NULL host/url in plain-TCP and async HTTP connect 2026-07-13 14:40:44 +08:00
Ashish Sharma e4304fab76 fix(mbedtls): validate crypto input lengths (TEE OOB, auth-bypass, overflows) 2026-07-13 14:40:44 +08:00
Ashish Sharma e382f878cc fix(esp_https_server): free TLS session on transport_ctx OOM in httpd_ssl_open 2026-07-13 14:40:44 +08:00
Ashish Sharma 35227e41e9 fix(esp_hal_security): clamp tag_len in aes_hal_gcm_read_tag to prevent OOB 2026-07-13 14:40:44 +08:00
Ashish Sharma bcfb0407f9 fix(bootloader_support): guard NULL efuse digest slot in secure-boot verify 2026-07-13 14:40:44 +08:00
Ashish Sharma ef4ecd0591 fix(esp_http_client): fix digest-auth leaks and credential/handle use-after-free 2026-07-13 14:40:44 +08:00
Ashish Sharma b589180b8b fix(esp_http_server): close UAF/double-free, buffer underflows, and OOB read 2026-07-13 14:40:44 +08:00
Ashish Sharma 9843bcc8dc fix(app_update): close OOB read, rollback-guard gap, and length underflow 2026-07-13 14:40:44 +08:00
hebinglin 0682c52828 fix(esp_hw_support): fix xtal unstable when carry 154 and ble cases 2026-07-13 12:11:49 +08:00
morris 0f3a788f16 fix(sdspi): reject oversized pre-read data before block receive
Guard start_command_read_blocks against cards that place TOKEN_BLOCK_START so early that extra_data_size exceeds the bytes expected on the current iteration. Without this check, the unsigned subtraction for will_receive underflows and propagates into memset, SPI transaction length, and memcpy counts against the fixed 516-byte block buffer.
2026-07-13 11:18:12 +08:00
morris f1cc319c2d fix(spi_slave): free DMA-private buffers when transaction queue is full
spi_slave_queue_trans calls spi_slave_setup_priv_trans to allocate
DMA buffers, then tries xQueueSend. If the queue is full the function
returns ESP_ERR_TIMEOUT without freeing those buffers, leaking up to
2 * max_transfer_sz per failed call. Call spi_slave_uninstall_priv_trans
before returning the timeout.
2026-07-13 11:18:12 +08:00
morris 2ab4b39ce5 fix(jpeg): release platform mutex on semaphore/pm-lock allocation failure
jpeg_acquire_codec_handle acquires s_jpeg_platform.mutex at entry
but two ESP_RETURN_ON_* macros (semaphore-create and PM-lock-create
failure) return without releasing it. Replace with ESP_GOTO_ON_*
that jumps to a cleanup label which frees partial resources, NULLs
the codec pointer, and releases the mutex.
2026-07-13 11:18:12 +08:00
morris cd28383088 fix(i2c): release platform mutex on intr/pm_lock delete failure
ESP_RETURN_ON_ERROR inside the s_i2c_platform.mutex critical section
returns without releasing the mutex, permanently blocking all I2C
bus operations. Replace with ESP_GOTO_ON_ERROR that jumps to a
cleanup label releasing the mutex before return.
2026-07-13 11:16:54 +08:00
morris 2c2f5ebf20 fix(csi): move csi_fsm init before resource allocation to fix err-path leak
CSI_FSM_INIT is 1, but the controller struct is zero-allocated.
Any failure before the former csi_fsm assignment (near the end of
esp_cam_new_csi_ctlr) jumped to err: which called s_del_csi_ctlr.
That function bailed out immediately because csi_fsm == 0, leaking
the claimed slot, queue, bridge, DMA channel, PM lock, and backup
buffer. Move csi_fsm = CSI_FSM_INIT right after a successful claim
so the err: path properly tears down all allocated resources.
2026-07-13 11:16:54 +08:00
morris 403074177f fix(adc): add missing input validation for channel and ret_handle
- adc_cali_curve_fitting: validate config->chan in check_valid() to
  prevent OOB access into s_adc_cali_chan_compens compensation table
- adc_filter: make s_adc_filter_free idempotent on !UNIT_BINDED SoCs
  to prevent double-free on repeated adc_del_continuous_iir_filter
- adc_cali_line_fitting(esp32): fix config && config typo to
  config && ret_handle, preventing NULL-pointer dereference
2026-07-13 11:16:54 +08:00
morris 1fb5dafdad chore: remove unused idf_test component
The idf_test component was previously cleaned up but accidentally
reintroduced when adding esp32s31 support. It only contained an empty
header file (idf_performance_target.h) with no references anywhere
in the codebase.

Also removes the corresponding entry from astyle-rules.yml.
2026-07-13 10:12:13 +08:00
Hu Rui c629c200a9 fix(touch): fix hw_ver1 read data check
Closes https://github.com/espressif/esp-idf/issues/18811
2026-07-10 20:01:33 +08:00
morris 8a420be0c7 refactor(emac): move sleep retention config into driver layer
Keep the EMAC regdma retention definitions in esp_eth so the backup
layout stays aligned with driver-owned sleep retention behavior.
2026-07-10 16:03:08 +08:00
Mahavir Jain 41582e1777 Merge branch 'ci/fix_esp_tee_cli_app_build_v6.1' into 'release/v6.1'
ci(esp_tee): Fix `tee_cli_app` build failure due to heap size overflow (v6.1)

See merge request espressif/esp-idf!50613
2026-07-10 11:56:40 +05:30
wuzhenghui b388afd2f3 fix(esp_hw_support): update memory pointer checks for SPM support 2026-07-10 14:19:47 +08:00
Laukik Hase 87a5664883 ci(esp_tee): Fix tee_cli_app build failure due to heap size overflow
- Also fix the `unused variable` warning while builing the PSA
  AES tests with `tee_test_fw` app
2026-07-10 10:30:02 +05:30
Mahavir Jain 33217d154f Merge branch 'fix/esp_http_client_header_buffer_too_small_v6.1' into 'release/v6.1'
feat(esp_http_client): detect oversized headers in tx buffer at send site (v6.1)

See merge request espressif/esp-idf!50313
2026-07-10 09:41:40 +05:30
Mahavir Jain 5288101bdc Merge branch 'fix/harden_esp_security_v6.1' into 'release/v6.1'
fix(esp_security): harden crypto peripheral error handling (v6.1)

See merge request espressif/esp-idf!50324
2026-07-10 09:39:59 +05:30
Mahavir Jain f0fbd9d9fa Merge branch 'fix/tls1_3_dynamic_buffer_server_crash_v6.1' into 'release/v6.1'
fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer (v6.1)

See merge request espressif/esp-idf!50386
2026-07-10 09:38:26 +05:30
David Cermak 0eafcb83e0 fix(lwip): tcp/ooseq: do not accept empty fin seg (+ other fixes)
* Update submodule: git log --oneline 9d2d8041..c6f2f878
  - test(lwip): add DHCP MTU validation unit test (espressif/esp-lwip@c6f2f878)
  - ppp: fix potential oob read in VJ decompression (espressif/esp-lwip@2ff439e6)
  - ip6-frag: Fix incorrect memcpy size to the actual struct (espressif/esp-lwip@91ad363b)
  - tcp/ooseq: do not accept empty fin seg (espressif/esp-lwip@fe4fb18c)
2026-07-09 16:04:37 +02:00
David Cermak 880b4cc2e9 fix(lwip): Adds nullchecks after DHCP server alloc'd pools 2026-07-09 16:04:37 +02:00
David Cermak d45d04dc43 fix(lwip): reject invalid DHCP MTU option values
Validate MTU from DHCP option 26 against RFC 2132 minimum (68 bytes)
before applying to netif->mtu, preventing rogue DHCP servers from
setting MTU to 0 or other dangerously low values that cause integer
wraparound in IPv4 fragmentation.
2026-07-09 16:04:37 +02:00
Hu Rui c73094392f fix(uhci): rx fsm race condition
Closes https://github.com/espressif/esp-idf/issues/18746
2026-07-09 18:55:12 +08:00
Jack 7ca1369ffc docs(esp_hw_support): fix IEEE 802.15.4 spelling and EUI-64 byte-range notation
Correct "802.154" to "802.15.4" and change the EUI-64 derivation notation
from base_mac[0:3]/base_mac[3:6] to the inclusive base_mac[0:2]/base_mac[3:5]
in the esp32h2/esp32h21/esp32h4 Kconfig.mac help text and the EN/zh_CN
misc_system_api docs.

Co-authored-by: Cursor <cursoragent@cursor.com>
(cherry picked from commit 811c64c17c)
2026-07-09 17:44:22 +08:00
Jack b5cd9ce7fa docs(esp_hw_support): document one-universal-MAC scheme and esp32s31 Four-option constraint
Add help text to the esp32h2/esp32h21/esp32h4 Kconfig.mac explaining
that these chips only consume one universally administered MAC address:
the IEEE 802.154 EUI-64 is derived from the base MAC and MAC_EXT, and
Bluetooth reuses the base MAC as-is (no BT offset, since there is no
Wi-Fi).

Add a matching 1-MAC derivation table and note to misc_system_api.rst
(EN and zh_CN) under a new `.. only:: esp32h2 or esp32h21 or esp32h4`
block, and exclude these targets from the generic 4/2 table.

Add an esp32s31-only note stating that the "Four" option may only be
used with a customer-provided custom base MAC range, since ESP32-S31
only provides two universally administered MAC addresses in eFuse.

Co-authored-by: Cursor <cursoragent@cursor.com>
(cherry picked from commit e3bc260178)
2026-07-09 17:44:22 +08:00
Jack 57184eb356 fix(esp_hw_support): use one universal MAC address for esp32h2/esp32h21/esp32h4
ESP32-H2/H21/H4 only provide a single universally administered MAC
address in eFuse (MAC_FACTORY), so switch their UNIVERSAL_MAC_ADDRESSES
Kconfig from "Two" to "One" to match the hardware allocation.

This is a functional no-op for MAC generation: the BT offset is only
applied when SOC_WIFI_SUPPORTED, and these chips have no Wi-Fi, so
Bluetooth already reuses the base MAC as-is; the IEEE 802.154 EUI-64 is
derived from the base MAC and MAC_EXT regardless. The only change is
the (otherwise unused) ESP_MAC_UNIVERSAL_MAC_ADDRESSES int value going
from 2 to 1.

Co-authored-by: Cursor <cursoragent@cursor.com>
(cherry picked from commit 431983a091)
2026-07-09 17:44:22 +08:00
Jack c7434cc9d9 fix(esp32s31): default UNIVERSAL_MAC_ADDRESSES to Two
ESP32-S31 only provides two universally administered MAC addresses in
eFuse. The previous default of "Four" led to WiFi softap and Ethernet
consuming global MAC slots (base+1/+3) that do not exist on this chip
and could collide with the Bluetooth MAC.

Switch the default to "Two" so Softap and Ethernet fall back to locally
administered MACs derived from the WiFi station and Bluetooth MACs.

The "Four" option is retained for customers who override the base MAC
with a custom range in which four universally administered MAC
addresses are allocated per device; the help text now documents this
constraint.

Co-authored-by: Cursor <cursoragent@cursor.com>
(cherry picked from commit f18f3814cc)
2026-07-09 17:44:22 +08:00
wuzhenghui 38421b8db7 change(heap): reserve DMA pool with low priority MALLOC_CAP_DEFAULT caps 2026-07-09 17:30:46 +08:00
Jin Cheng e4c999e891 fix(bt/bluedroid): fixed OOB read in PBAP app parameter parsing
Closes SEC-713
2026-07-09 15:44:57 +08:00
Jin Cheng b6a8e896e7 fix(bt/bluedroid): fixed stuck sec_state on authention HCI command send failure
Closes SEC-1164
2026-07-09 15:44:57 +08:00
Jin Cheng 02841cdf50 fix(bt/bluedroid): fixed HID host slot leak on local VUP ACL drop
Closes SEC-1169
2026-07-09 15:44:57 +08:00
Jin Cheng 81c8d1b999 fix(bt/bluedroid): fixed NULL dereference in remote legacy authentication handler
Closes SEC-1143
2026-07-09 15:44:57 +08:00
Jin Cheng 91d80bf874 fix(bt/bluedroid): fixed integer overflow in HID report descriptor parser
Closes SEC-084
2026-07-09 15:44:57 +08:00
Jin Cheng a0ba14e55d fix(bt/bluedroid): fixed wrong link key flag cleared on legacy BR/EDR authentication failure
Stale bond trust state cound remain after authenticaion failure, causing
incorrect bond status and link key auto-reply behavior.

Closes SEC-1153
2026-07-09 15:44:57 +08:00
Mahavir Jain 6fa5704eda Merge branch 'feat/enable_aes_gcm_support_for_esp32s31_v6.1' into 'release/v6.1'
feat: enable AES GCM support for ESP32-S31 (v6.1)

See merge request espressif/esp-idf!50399
2026-07-09 12:29:16 +05:30
Mahavir Jain 9a567fbb87 Merge branch 'feat/update_documentation_and_cleanup_for_esp32h4_v6.1' into 'release/v6.1'
Feat/update documentation and cleanup for esp32h4 (v6.1)

See merge request espressif/esp-idf!50398
2026-07-09 12:02:43 +05:30
Mahavir Jain eda926af1c Merge branch 'fix/fix_esp_tee_failing_deterministic_ecdsa_sign_v6.1' into 'release/v6.1'
fix(esp_tee): release SHA held by HMAC after crypto peripheral reset (v6.1)

See merge request espressif/esp-idf!50317
2026-07-09 11:52:38 +05:30
Mahavir Jain ab92370b33 Merge branch 'fix/revert_redundant_rom_pmp_18769_v6.1' into 'release/v6.1'
revert(esp_hw_support): Re-add separate D-ROM PMP entry on C6/H2 (v6.1)

See merge request espressif/esp-idf!50359
2026-07-09 11:52:14 +05:30
Xu Si Yu e86d37d6da fix(openthread): disable software retx security in spinel-only config 2026-07-09 11:32:38 +08:00
Xu Si Yu 52237ad3d8 feat(openthread): update thread-lib for upstream b678a4f6
* esp-openthread: thread_zigbee/esp-openthread@47428f1e8
* openthread: espressif/openthread@b678a4f63
* esp-idf: espressif/esp-idf@3821049b9
2026-07-08 12:57:08 +00:00
Xu Si Yu 3821049b98 feat(openthread): update openthread submodule 2026-07-08 20:38:35 +08:00
Xu Si Yu 5a5cb088b4 fix(openthread): fix TREL peer discovery by selecting IPv6 from mDNS address list 2026-07-08 20:38:35 +08:00
yangfeng 8a3d288843 fix(bt/example): Add print the device name to verify if it matches in HID example 2026-07-08 15:28:00 +08:00
Tomáš Rohlínek f98cfec679 fix(storage/fatfs): fix FAT32 mount integer overflow (CVE-2026-6682)
The initial CVE-2026-6682 fix hardened the exFAT mount path, but the CVE
as reported by runZero is a FAT32 defect in mount_volume() and is
reachable in the default configuration (exFAT and 64-bit LBA disabled).
This corrects the fix.

Root cause: `fasize *= fs->n_fats` is a DWORD multiply with no overflow
guard. A crafted BPB_FATSz32 such as 0x80000001 with NumFATs=2 wraps
`fasize` to 0x00000002. The wrapped (too-small) FAT size places
`fs->database` inside the FAT region, so a forged directory entry yields
an attacker-controlled `finfo.fsize`; a caller using it as a read length
overflows its buffer with attacker-controlled bytes (CVSS 7.6).

Fix: reject per-FAT and reserved+FAT+root system-area sizes that overflow
DWORD before they are used to derive the data-area base. The exFAT
cluster-heap/bitmap 64-bit promotions are retained as defense-in-depth
and relabeled (they are not CVE-2026-6682). SBOM reason updated.
2026-07-07 16:36:31 +02:00