Commit Graph
42899 Commits
Author SHA1 Message Date
yi chen 5259ebd1e7 fix(wear_levelling): guard WL_Flash::write()/read() against size==0 underflow
WL_Flash::write() and WL_Flash::read() computed:

    uint32_t count = (size - 1) / this->cfg.wl_page_size;

`size` is `size_t` (unsigned). Neither the public wl_write()/wl_read() API
(wear_levelling.cpp), nor the newer wl_bdl_write()/wl_bdl_read() block-device
path (wl_blockdev.cpp), reject size == 0 before calling into WL_Flash, and
wear_levelling.h does not document size == 0 as invalid (a 0-byte
write/read is a reasonable no-op, mirroring POSIX write()/read() with
count == 0).

When size == 0, `size - 1` wraps around to SIZE_MAX, so `count` becomes an
enormous page count instead of 0. The functions then loop that many times,
reading (write()) or writing (read()) `wl_page_size` bytes per iteration
through the flash partition, immediately walking past the caller-supplied
buffer on the very first iteration:

  - write(): out-of-bounds *read* from the caller's `src` buffer.
  - read():  out-of-bounds *write* into the caller's `dest` buffer -- the
             more severe case, since it corrupts caller memory with flash
             content instead of merely over-reading.

Verified with a standalone reproduction that compiles the unmodified
WL_Flash.cpp against a mock Flash_Access partition: calling
`wl.write(0, an_8_byte_buffer, 0)` with no other change immediately
segfaults (confirmed count == 0xFFFFFFFF for wl_page_size == 4096); with
this fix applied the same call returns ESP_OK without touching memory
outside the buffer, and normal non-zero-size read/write is unaffected.

Add an early `size == 0` return (mirroring the existing `!initialized`
guard) to both functions, and a host_test regression case exercising
wl_write()/wl_read() with size == 0 through the public API.

Disclosure: this fix was prepared with AI assistance (Claude) and reviewed
by me before submission.

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-14 12:23:53 +02:00
Zhi Wei Jian 607c5833ef feat(ble/bluedroid): Add bluedroid dual identify server example
(cherry picked from commit 1de0d2fef7)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 15:01:30 +08:00
zhiweijian bfdb6f5c9e fix(ble/bluedroid): guard GATT database hash and serialization 2026-07-14 14:59:15 +08:00
Zhi Wei Jian 329c1c8f8e feat(ble/bluedroid): Support bluedroid dual identity
(cherry picked from commit 2358786647)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 14:26:15 +08:00
Rahul Tank 43280d9be8 Merge branch 'bugfix/fix_bond_store_overflow_v5.3' into 'release/v5.3'
fix(nimble): Fix bond-store overflow when IRK is enabled (v5.3)

See merge request espressif/esp-idf!50627
2026-07-14 11:17:48 +05:30
Zhi Wei Jian ebd9ca130e fix(ble/bluedroid): use BOOLEAN for BLE HCI command builders
(cherry picked from commit abbf001120)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:55 +08:00
Zhi Wei Jian 5f7deedd8b fix(ble/bluedroid): clean up LE CoC connect on CCB alloc failure
(cherry picked from commit 4fd1ebb4a9)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:54 +08:00
Zhi Wei Jian f080478455 docs(ble/bluedroid): note ISO BIG HCI alloc failure not checked
(cherry picked from commit 34b59d30ae)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:54 +08:00
Zhi Wei Jian ea9fdcd2e0 fix(ble/bluedroid): fix direct-connect cleanup and adv bounds
(cherry picked from commit 82e71c1767)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:54 +08:00
Zhi Wei Jian 1f3d235a9f fix(ble/bluedroid): validate BLE confirm/OOB and sec-check device
(cherry picked from commit 93ab11d564)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:53 +08:00
Zhi Wei Jian 7e677879a6 fix(ble/bluedroid): validate SMP pair-fail reason and OOB device
(cherry picked from commit 98efe02385)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:53 +08:00
Zhi Wei Jian de4598284a fix(ble/bluedroid): route ATT indication-conf timeout separately
(cherry picked from commit 6c3267ee84)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:52 +08:00
Zhi Wei Jian 315ff40e71 fix(ble/bluedroid): validate ATT PDU sizes
(cherry picked from commit bb00b9817d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:52 +08:00
Zhi Wei Jian c3d78e8c66 fix(ble/bluedroid): re-lookup GATT TCB after enc-complete callback
(cherry picked from commit 37562af0ea)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:52 +08:00
Zhi Wei Jian 80992db5a6 fix(ble/bluedroid): fix GATT long read and Service Changed CCC
(cherry picked from commit 4ce692ac0c)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:51 +08:00
Zhi Wei Jian c5ee2be0ed fix(ble/bluedroid): validate GATT client discovery handles
(cherry picked from commit ac35ae6f2d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:51 +08:00
Zhi Wei Jian c202b37fa8 fix(ble/bluedroid): cap Read By Type length and free failed service decl
(cherry picked from commit 27ff0cf8c7)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:51 +08:00
Zhi Wei Jian 6fa7f4195d fix(ble/bluedroid): fix GATT server busy errors and sr_cmd handling
(cherry picked from commit f86739b03d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:50 +08:00
Zhi Wei Jian a6fed3daae fix(ble/bluedroid): fix GATT teardown and service-change flow
(cherry picked from commit 0645ba469d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:50 +08:00
Zhi Wei Jian 0927c1990d fix(ble/bluedroid): fix GATT service lifecycle leaks
(cherry picked from commit ac93d94958)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:49 +08:00
Zhi Wei Jian c33e3c13bc fix(ble/bluedroid): add GATT resource-cleanup helpers
(cherry picked from commit b83327f3ca)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 12:03:49 +08:00
Zhi Wei Jian 1b3a7a04c2 feat(ble/bluedroid): Support bluedroid LE COC and EATT features
(cherry picked from commit 83f0831c53)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-07-14 11:56:00 +08:00
Zhang Hai Peng 58a777febf fix(ble/bluedroid): downgrade numeric comparison log to warning
(cherry picked from commit 72a49ed53b)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:37:04 +08:00
Zhang Hai Peng f6f9236099 fix(ble/bluedroid): preserve ext adv state when set params fails
Only update extend_adv_cb after HCI Set Extended Advertising
Parameters succeeds, so a failed update does not corrupt cached
legacy_pdu and related fields used by adv data validation.


(cherry picked from commit 31bd80fee8)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:37:02 +08:00
Zhang Hai Peng 0b0eaf2db4 fix(ble/bluedroid): reject invalid ATT error code 0x00 on client
Map received error reason 0x00 to GATT_UNKNOWN_ERROR so the client
does not report GATT_SUCCESS with zero-length data on malformed errors.


(cherry picked from commit 1b6f9380f4)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:03 +08:00
Zhang Hai Peng 01066c125b fix(ble/bluedroid): use sr_cmd status for GATT server error rsp
When sending an ATT error response after a failed server operation,
use p_tcb->sr_cmd.status instead of the last app callback status so
invalid error code 0x00 is not sent to the peer.


(cherry picked from commit 4c0488d92a)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:03 +08:00
Zhang Hai Peng 2fe6c39b83 fix(ble/bluedroid): match read-multiple-var responses by handle
(cherry picked from commit 979c7dc567)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:02 +08:00
Zhang Hai Peng bc4889662b fix(ble/bluedroid): match read-multiple responses by handle
Read Multiple may mix stack auto-responses with app async responses,
so multi_rsp_q order can differ from the request handle order. Look up
each response by handle (with occurrence for duplicates) instead of
walking the queue by index, and treat opcode-only buffers as empty.


(cherry picked from commit f91a41510c)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-14 10:36:01 +08:00
Island 28e501b89d Merge branch 'ble-log-console-migration-notice_v5.3' into 'release/v5.3'
Ble log console repository migration (5.3)

See merge request espressif/esp-idf!50604
2026-07-14 10:20:38 +08:00
Island 9c65614fa5 Merge branch 'fix/ble_mesh_fixed_issues_v5.3' into 'release/v5.3'
Resolve reported BLE mesh stack issues (5.3)

See merge request espressif/esp-idf!50404
2026-07-14 10:16:53 +08:00
yi chen 7206555ae8 fix(vfs): use MAX_FDS instead of VFS_MAX_COUNT when clearing fd table on unregister
esp_vfs_unregister_with_id() scanned only the first VFS_MAX_COUNT
(default 8, max 20) slots of s_fd_table[MAX_FDS] (MAX_FDS = FD_SETSIZE,
64 on non-Cygwin targets) when clearing stale references to the
unregistered VFS. Every other loop over s_fd_table in this file
(and in vfs_calls.c) correctly bounds on MAX_FDS.

Any global fd >= VFS_MAX_COUNT that was still open against the VFS
being unregistered was left with a stale vfs_index pointing at a slot
that esp_get_free_index() can immediately hand out to the next
esp_vfs_register*() call, causing later operations on that fd to be
routed into an unrelated filesystem's context.

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-13 15:59:26 +02:00
Guilherme Ferreira 724897ecc2 fix(esp_eth): recover W5500 RX path on corrupted frame length
Reject an implausible SPI-read frame-length header and drain the
socket RX buffer to resync Sn_RX_RD, instead of looping forever on
the unrecoverable descriptor and starving the system.
2026-07-10 23:06:13 +00:00
Euripedes Rocha b6234bb6fc Merge branch 'fix/sec-347-hostname-null-check_v5.3' into 'release/v5.3'
fix(esp_netif): reject NULL hostname in esp_netif_set_hostname_api (SEC_347) (v5.3)

See merge request espressif/esp-idf!50593
2026-07-10 14:14:51 +02:00
Euripedes Rocha Filho 53e0944889 fix(esp_netif): Removes double-free path and NULL dereference in bridge 2026-07-10 14:13:13 +02:00
Chen Jichang 0dad295632 fix(i2c_oled): fix example hang when i2c transaction fails
Closes https://github.com/espressif/esp-idf/issues/18713
2026-07-10 17:57:11 +08:00
wuzhenghui a3515f31fb fix(esp_hw_support): update memory pointer checks for SPM support 2026-07-10 17:18:42 +08:00
Rahul Tank dd42e3ced3 fix(nimble): Fix bond-store overflow when IRK is enabled 2026-07-10 13:31:39 +05:30
guozifan e654698551 remove(ble): migrate BLE Log Console out of ESP-IDF 2026-07-10 15:37:26 +08:00
morris e11c30437a Merge branch 'fix/uhci_rx_fsm_v5.3' into 'release/v5.3'
fix(uhci): rx fsm race condition (v5.3)

See merge request espressif/esp-idf!50581
2026-07-10 11:22:38 +08:00
Jiang Jiang Jian f6bad005cf Merge branch 'change/change_regdma_malloc_caps_v5.3' into 'release/v5.3'
change(esp_hw_support): change regdma malloc caps to allow getting memory in the DMA pool (v5.3)

See merge request espressif/esp-idf!50261
2026-07-10 10:28:44 +08:00
David Cermak 2e2d398904 fix(lwip): Adds nullchecks after DHCP server alloc'd pools 2026-07-09 16:09:22 +02:00
David Cermak 3c4d786a2c fix(lwip): reject invalid DHCP MTU option values
Validate MTU from DHCP option 26 against RFC 2132 minimum (68 bytes)
before applying to netif->mtu, preventing rogue DHCP servers from
setting MTU to 0 or other dangerously low values that cause integer
wraparound in IPv4 fragmentation.
2026-07-09 16:09:21 +02:00
Euripedes Rocha Filho 5e65088205 fix(esp_netif): reject NULL hostname in esp_netif_set_hostname_api
esp_netif_set_hostname_api() dereferenced hostname via strlen() without
checking it for NULL first, causing a NULL pointer dereference.
2026-07-09 16:08:17 +02:00
Hu Rui 9bcf04ab89 fix(uhci): rx fsm race condition
Closes https://github.com/espressif/esp-idf/issues/18746
2026-07-09 19:06:08 +08:00
Zhang Wen Xu b6860b2db5 Merge branch 'feat/update_openthread_submodule_and_br_lib_20260624_v5.3' into 'release/v5.3'
feat(openthread): update openthread submodule (v5.3)

See merge request espressif/esp-idf!50521
2026-07-09 10:16:54 +00:00
Mahavir Jain 6f389eb69b Merge branch 'change/sbom_exclude_fixed_cves_v5.3' into 'release/v5.3'
change(sbom): exclude ESP-IDF CVEs already fixed on release/v5.3 (v5.3)

See merge request espressif/esp-idf!50573
2026-07-09 15:28:01 +05:30
Frantisek Hrbata 94ce057ccc change(sbom): exclude ESP-IDF CVEs already fixed on release/v5.3
esp-idf-sbom reports four ESP-IDF CVEs against this branch because NVD
pins them to 5.3.5 -- the version release/v5.3 still reports until 5.3.6
is released -- even though the fixes are already merged here:

  - CVE-2026-45160  DHCP server OOB read (9f713dbc94)
  - CVE-2026-45541  esp_http_server WebSocket NULL dereference (f88a47e4f3)
  - CVE-2026-45542  protocomm SRP6a heap overflow (0ea58d7984)
  - CVE-2026-46532  BlueDroid AVRCP vendor-command parser OOB read (7c004d3fe3)

esp-idf-sbom merges this repository-local excluded_cves.yaml into its
exclusion list when scanning the tree, so these CVEs are reported as
excluded for this branch while the released v5.3.5 tag, which predates
this file, is still reported. Once version.cmake is bumped to 5.3.6 the
entries become no-ops (NVD does not list 5.3.6) and can be removed.

Compared to the release/v5.5 file this backport was adapted from, the
two ESP-TEE CVEs do not apply (NVD pins them to 5.5.4 and 6.0 only) and
CVE-2026-46532 is added (fixed in the released v5.5.4, but only after
v5.3.5 on this branch).

Signed-off-by: Frantisek Hrbata <frantisek.hrbata@espressif.com>
2026-07-09 11:52:14 +02:00
wuzhenghui 82712313ea change(heap): reserve DMA pool with low priority MALLOC_CAP_DEFAULT caps 2026-07-09 17:37:14 +08:00
Jin Cheng ff88e7a635 fix(bt/bluedroid): fixed stuck sec_state on authention HCI command send failure
Closes SEC-1164
2026-07-09 17:20:40 +08:00
Jin Cheng db6cd2a300 fix(bt/bluedroid): fixed HID host slot leak on local VUP ACL drop
Closes SEC-1169
2026-07-09 17:20:40 +08:00