Only update extend_adv_cb after HCI Set Extended Advertising
Parameters succeeds, so a failed update does not corrupt cached
legacy_pdu and related fields used by adv data validation.
(cherry picked from commit 31bd80fee8)
Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
Map received error reason 0x00 to GATT_UNKNOWN_ERROR so the client
does not report GATT_SUCCESS with zero-length data on malformed errors.
(cherry picked from commit 1b6f9380f4)
Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
When sending an ATT error response after a failed server operation,
use p_tcb->sr_cmd.status instead of the last app callback status so
invalid error code 0x00 is not sent to the peer.
(cherry picked from commit 4c0488d92a)
Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
Read Multiple may mix stack auto-responses with app async responses,
so multi_rsp_q order can differ from the request handle order. Look up
each response by handle (with occurrence for duplicates) instead of
walking the queue by index, and treat opcode-only buffers as empty.
(cherry picked from commit f91a41510c)
Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
esp_vfs_unregister_with_id() scanned only the first VFS_MAX_COUNT
(default 8, max 20) slots of s_fd_table[MAX_FDS] (MAX_FDS = FD_SETSIZE,
64 on non-Cygwin targets) when clearing stale references to the
unregistered VFS. Every other loop over s_fd_table in this file
(and in vfs_calls.c) correctly bounds on MAX_FDS.
Any global fd >= VFS_MAX_COUNT that was still open against the VFS
being unregistered was left with a stale vfs_index pointing at a slot
that esp_get_free_index() can immediately hand out to the next
esp_vfs_register*() call, causing later operations on that fd to be
routed into an unrelated filesystem's context.
Signed-off-by: yi chen <94xhn1@gmail.com>
Reject an implausible SPI-read frame-length header and drain the
socket RX buffer to resync Sn_RX_RD, instead of looping forever on
the unrecoverable descriptor and starving the system.
Validate MTU from DHCP option 26 against RFC 2132 minimum (68 bytes)
before applying to netif->mtu, preventing rogue DHCP servers from
setting MTU to 0 or other dangerously low values that cause integer
wraparound in IPv4 fragmentation.
esp-idf-sbom reports four ESP-IDF CVEs against this branch because NVD
pins them to 5.3.5 -- the version release/v5.3 still reports until 5.3.6
is released -- even though the fixes are already merged here:
- CVE-2026-45160 DHCP server OOB read (9f713dbc94)
- CVE-2026-45541 esp_http_server WebSocket NULL dereference (f88a47e4f3)
- CVE-2026-45542 protocomm SRP6a heap overflow (0ea58d7984)
- CVE-2026-46532 BlueDroid AVRCP vendor-command parser OOB read (7c004d3fe3)
esp-idf-sbom merges this repository-local excluded_cves.yaml into its
exclusion list when scanning the tree, so these CVEs are reported as
excluded for this branch while the released v5.3.5 tag, which predates
this file, is still reported. Once version.cmake is bumped to 5.3.6 the
entries become no-ops (NVD does not list 5.3.6) and can be removed.
Compared to the release/v5.5 file this backport was adapted from, the
two ESP-TEE CVEs do not apply (NVD pins them to 5.5.4 and 6.0 only) and
CVE-2026-46532 is added (fixed in the released v5.5.4, but only after
v5.3.5 on this branch).
Signed-off-by: Frantisek Hrbata <frantisek.hrbata@espressif.com>