Commit Graph
1 Commits
Author SHA1 Message Date
Frantisek Hrbata 6e2f4b2c89 change(sbom): exclude ESP-IDF CVEs already fixed on release/v5.4
esp-idf-sbom reports four ESP-IDF CVEs against this branch because NVD
pins them to 5.4.4 -- the version release/v5.4 still reports until 5.4.5
is released -- even though the fixes are already merged here:

  - CVE-2026-45160  DHCP server OOB read (2bf4dd1200)
  - CVE-2026-45541  esp_http_server WebSocket NULL dereference (37508ab911)
  - CVE-2026-45542  protocomm SRP6a heap overflow (f5d24a7e91)
  - CVE-2026-46532  BlueDroid AVRCP vendor-command parser OOB read (56053c4d1f)

esp-idf-sbom merges this repository-local excluded_cves.yaml into its
exclusion list when scanning the tree, so these CVEs are reported as
excluded for this branch while the released v5.4.4 tag, which predates
this file, is still reported. Once version.cmake is bumped to 5.4.5 the
entries become no-ops (NVD does not list 5.4.5) and can be removed.

Compared to the release/v5.5 file this backport was adapted from, the
two ESP-TEE CVEs do not apply (NVD pins them to 5.5.4 and 6.0 only) and
CVE-2026-46532 is added (fixed in the released v5.5.4, but only after
v5.4.4 on this branch).

Signed-off-by: Frantisek Hrbata <frantisek.hrbata@espressif.com>
2026-07-09 11:51:33 +02:00