esp-idf-sbom reports four ESP-IDF CVEs against this branch because NVD
pins them to 5.4.4 -- the version release/v5.4 still reports until 5.4.5
is released -- even though the fixes are already merged here:
- CVE-2026-45160 DHCP server OOB read (2bf4dd1200)
- CVE-2026-45541 esp_http_server WebSocket NULL dereference (37508ab911)
- CVE-2026-45542 protocomm SRP6a heap overflow (f5d24a7e91)
- CVE-2026-46532 BlueDroid AVRCP vendor-command parser OOB read (56053c4d1f)
esp-idf-sbom merges this repository-local excluded_cves.yaml into its
exclusion list when scanning the tree, so these CVEs are reported as
excluded for this branch while the released v5.4.4 tag, which predates
this file, is still reported. Once version.cmake is bumped to 5.4.5 the
entries become no-ops (NVD does not list 5.4.5) and can be removed.
Compared to the release/v5.5 file this backport was adapted from, the
two ESP-TEE CVEs do not apply (NVD pins them to 5.5.4 and 6.0 only) and
CVE-2026-46532 is added (fixed in the released v5.5.4, but only after
v5.4.4 on this branch).
Signed-off-by: Frantisek Hrbata <frantisek.hrbata@espressif.com>