Commit Graph
53505 Commits
Author SHA1 Message Date
Mahavir Jain 41582e1777 Merge branch 'ci/fix_esp_tee_cli_app_build_v6.1' into 'release/v6.1'
ci(esp_tee): Fix `tee_cli_app` build failure due to heap size overflow (v6.1)

See merge request espressif/esp-idf!50613
2026-07-10 11:56:40 +05:30
wuzhenghui b388afd2f3 fix(esp_hw_support): update memory pointer checks for SPM support 2026-07-10 14:19:47 +08:00
Laukik Hase 87a5664883 ci(esp_tee): Fix tee_cli_app build failure due to heap size overflow
- Also fix the `unused variable` warning while builing the PSA
  AES tests with `tee_test_fw` app
2026-07-10 10:30:02 +05:30
Mahavir Jain 33217d154f Merge branch 'fix/esp_http_client_header_buffer_too_small_v6.1' into 'release/v6.1'
feat(esp_http_client): detect oversized headers in tx buffer at send site (v6.1)

See merge request espressif/esp-idf!50313
2026-07-10 09:41:40 +05:30
Mahavir Jain 5288101bdc Merge branch 'fix/harden_esp_security_v6.1' into 'release/v6.1'
fix(esp_security): harden crypto peripheral error handling (v6.1)

See merge request espressif/esp-idf!50324
2026-07-10 09:39:59 +05:30
Mahavir Jain f0fbd9d9fa Merge branch 'fix/tls1_3_dynamic_buffer_server_crash_v6.1' into 'release/v6.1'
fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer (v6.1)

See merge request espressif/esp-idf!50386
2026-07-10 09:38:26 +05:30
David Cermak 0eafcb83e0 fix(lwip): tcp/ooseq: do not accept empty fin seg (+ other fixes)
* Update submodule: git log --oneline 9d2d8041..c6f2f878
  - test(lwip): add DHCP MTU validation unit test (espressif/esp-lwip@c6f2f878)
  - ppp: fix potential oob read in VJ decompression (espressif/esp-lwip@2ff439e6)
  - ip6-frag: Fix incorrect memcpy size to the actual struct (espressif/esp-lwip@91ad363b)
  - tcp/ooseq: do not accept empty fin seg (espressif/esp-lwip@fe4fb18c)
2026-07-09 16:04:37 +02:00
David Cermak 880b4cc2e9 fix(lwip): Adds nullchecks after DHCP server alloc'd pools 2026-07-09 16:04:37 +02:00
David Cermak d45d04dc43 fix(lwip): reject invalid DHCP MTU option values
Validate MTU from DHCP option 26 against RFC 2132 minimum (68 bytes)
before applying to netif->mtu, preventing rogue DHCP servers from
setting MTU to 0 or other dangerously low values that cause integer
wraparound in IPv4 fragmentation.
2026-07-09 16:04:37 +02:00
Hu Rui c73094392f fix(uhci): rx fsm race condition
Closes https://github.com/espressif/esp-idf/issues/18746
2026-07-09 18:55:12 +08:00
Jack 7ca1369ffc docs(esp_hw_support): fix IEEE 802.15.4 spelling and EUI-64 byte-range notation
Correct "802.154" to "802.15.4" and change the EUI-64 derivation notation
from base_mac[0:3]/base_mac[3:6] to the inclusive base_mac[0:2]/base_mac[3:5]
in the esp32h2/esp32h21/esp32h4 Kconfig.mac help text and the EN/zh_CN
misc_system_api docs.

Co-authored-by: Cursor <cursoragent@cursor.com>
(cherry picked from commit 811c64c17c)
2026-07-09 17:44:22 +08:00
Jack b5cd9ce7fa docs(esp_hw_support): document one-universal-MAC scheme and esp32s31 Four-option constraint
Add help text to the esp32h2/esp32h21/esp32h4 Kconfig.mac explaining
that these chips only consume one universally administered MAC address:
the IEEE 802.154 EUI-64 is derived from the base MAC and MAC_EXT, and
Bluetooth reuses the base MAC as-is (no BT offset, since there is no
Wi-Fi).

Add a matching 1-MAC derivation table and note to misc_system_api.rst
(EN and zh_CN) under a new `.. only:: esp32h2 or esp32h21 or esp32h4`
block, and exclude these targets from the generic 4/2 table.

Add an esp32s31-only note stating that the "Four" option may only be
used with a customer-provided custom base MAC range, since ESP32-S31
only provides two universally administered MAC addresses in eFuse.

Co-authored-by: Cursor <cursoragent@cursor.com>
(cherry picked from commit e3bc260178)
2026-07-09 17:44:22 +08:00
Jack 57184eb356 fix(esp_hw_support): use one universal MAC address for esp32h2/esp32h21/esp32h4
ESP32-H2/H21/H4 only provide a single universally administered MAC
address in eFuse (MAC_FACTORY), so switch their UNIVERSAL_MAC_ADDRESSES
Kconfig from "Two" to "One" to match the hardware allocation.

This is a functional no-op for MAC generation: the BT offset is only
applied when SOC_WIFI_SUPPORTED, and these chips have no Wi-Fi, so
Bluetooth already reuses the base MAC as-is; the IEEE 802.154 EUI-64 is
derived from the base MAC and MAC_EXT regardless. The only change is
the (otherwise unused) ESP_MAC_UNIVERSAL_MAC_ADDRESSES int value going
from 2 to 1.

Co-authored-by: Cursor <cursoragent@cursor.com>
(cherry picked from commit 431983a091)
2026-07-09 17:44:22 +08:00
Jack c7434cc9d9 fix(esp32s31): default UNIVERSAL_MAC_ADDRESSES to Two
ESP32-S31 only provides two universally administered MAC addresses in
eFuse. The previous default of "Four" led to WiFi softap and Ethernet
consuming global MAC slots (base+1/+3) that do not exist on this chip
and could collide with the Bluetooth MAC.

Switch the default to "Two" so Softap and Ethernet fall back to locally
administered MACs derived from the WiFi station and Bluetooth MACs.

The "Four" option is retained for customers who override the base MAC
with a custom range in which four universally administered MAC
addresses are allocated per device; the help text now documents this
constraint.

Co-authored-by: Cursor <cursoragent@cursor.com>
(cherry picked from commit f18f3814cc)
2026-07-09 17:44:22 +08:00
wuzhenghui 38421b8db7 change(heap): reserve DMA pool with low priority MALLOC_CAP_DEFAULT caps 2026-07-09 17:30:46 +08:00
Jin Cheng e4c999e891 fix(bt/bluedroid): fixed OOB read in PBAP app parameter parsing
Closes SEC-713
2026-07-09 15:44:57 +08:00
Jin Cheng b6a8e896e7 fix(bt/bluedroid): fixed stuck sec_state on authention HCI command send failure
Closes SEC-1164
2026-07-09 15:44:57 +08:00
Jin Cheng 02841cdf50 fix(bt/bluedroid): fixed HID host slot leak on local VUP ACL drop
Closes SEC-1169
2026-07-09 15:44:57 +08:00
Jin Cheng 81c8d1b999 fix(bt/bluedroid): fixed NULL dereference in remote legacy authentication handler
Closes SEC-1143
2026-07-09 15:44:57 +08:00
Jin Cheng 91d80bf874 fix(bt/bluedroid): fixed integer overflow in HID report descriptor parser
Closes SEC-084
2026-07-09 15:44:57 +08:00
Jin Cheng a0ba14e55d fix(bt/bluedroid): fixed wrong link key flag cleared on legacy BR/EDR authentication failure
Stale bond trust state cound remain after authenticaion failure, causing
incorrect bond status and link key auto-reply behavior.

Closes SEC-1153
2026-07-09 15:44:57 +08:00
Mahavir Jain 6fa5704eda Merge branch 'feat/enable_aes_gcm_support_for_esp32s31_v6.1' into 'release/v6.1'
feat: enable AES GCM support for ESP32-S31 (v6.1)

See merge request espressif/esp-idf!50399
2026-07-09 12:29:16 +05:30
Mahavir Jain 9a567fbb87 Merge branch 'feat/update_documentation_and_cleanup_for_esp32h4_v6.1' into 'release/v6.1'
Feat/update documentation and cleanup for esp32h4 (v6.1)

See merge request espressif/esp-idf!50398
2026-07-09 12:02:43 +05:30
Mahavir Jain eda926af1c Merge branch 'fix/fix_esp_tee_failing_deterministic_ecdsa_sign_v6.1' into 'release/v6.1'
fix(esp_tee): release SHA held by HMAC after crypto peripheral reset (v6.1)

See merge request espressif/esp-idf!50317
2026-07-09 11:52:38 +05:30
Mahavir Jain ab92370b33 Merge branch 'fix/revert_redundant_rom_pmp_18769_v6.1' into 'release/v6.1'
revert(esp_hw_support): Re-add separate D-ROM PMP entry on C6/H2 (v6.1)

See merge request espressif/esp-idf!50359
2026-07-09 11:52:14 +05:30
Xu Si Yu e86d37d6da fix(openthread): disable software retx security in spinel-only config 2026-07-09 11:32:38 +08:00
Xu Si Yu 52237ad3d8 feat(openthread): update thread-lib for upstream b678a4f6
* esp-openthread: thread_zigbee/esp-openthread@47428f1e8
* openthread: espressif/openthread@b678a4f63
* esp-idf: espressif/esp-idf@3821049b9
2026-07-08 12:57:08 +00:00
Xu Si Yu 3821049b98 feat(openthread): update openthread submodule 2026-07-08 20:38:35 +08:00
Xu Si Yu 5a5cb088b4 fix(openthread): fix TREL peer discovery by selecting IPv6 from mDNS address list 2026-07-08 20:38:35 +08:00
yangfeng 8a3d288843 fix(bt/example): Add print the device name to verify if it matches in HID example 2026-07-08 15:28:00 +08:00
Tomáš Rohlínek f98cfec679 fix(storage/fatfs): fix FAT32 mount integer overflow (CVE-2026-6682)
The initial CVE-2026-6682 fix hardened the exFAT mount path, but the CVE
as reported by runZero is a FAT32 defect in mount_volume() and is
reachable in the default configuration (exFAT and 64-bit LBA disabled).
This corrects the fix.

Root cause: `fasize *= fs->n_fats` is a DWORD multiply with no overflow
guard. A crafted BPB_FATSz32 such as 0x80000001 with NumFATs=2 wraps
`fasize` to 0x00000002. The wrapped (too-small) FAT size places
`fs->database` inside the FAT region, so a forged directory entry yields
an attacker-controlled `finfo.fsize`; a caller using it as a read length
overflows its buffer with attacker-controlled bytes (CVSS 7.6).

Fix: reject per-FAT and reserved+FAT+root system-area sizes that overflow
DWORD before they are used to derive the data-area base. The exFAT
cluster-heap/bitmap 64-bit promotions are retained as defense-in-depth
and relabeled (they are not CVE-2026-6682). SBOM reason updated.
2026-07-07 16:36:31 +02:00
Ashish Sharma 1041b69131 feat(esp_http_client): detect oversized headers in tx buffer while sending request 2026-07-07 18:22:08 +08:00
wuzhenghui c5ffc85029 feat(soc): update PMU & PAU register description 2026-07-06 21:20:58 +08:00
wuzhenghui 7c23080017 fix(esp_hw_support): fix esp32s31 mpll initialization 2026-07-06 21:17:34 +08:00
Tomáš Rohlínek f9d3c54b3e fix(storage/fatfs): record non-applicable runZero 2026 CVEs in SBOM
Document the three runZero "Seven FatFs bugs" CVEs that require no source change
in this component, so vulnerability scanners have their disposition:

  - CVE-2026-6684: GPT partition-scan loop DoS. Already fixed upstream in R0.16,
    where test_gpt_header() caps the partition-entry count at 128.
  - CVE-2026-6686: read of uninitialized clusters after f_lseek() past EOF.
    Longstanding, behavioral; not a memory-safety defect and zero-filling every
    extended cluster is prohibitively costly on flash.
  - CVE-2026-6688: long-filename overflow in downstream callers. Not exposed in
    ESP-IDF; vfs_fat.c uses bounded copies and fname is bounded by FF_MAX_LFN.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:40:51 +02:00
Tomáš Rohlínek 01f386cc1f fix(storage/fatfs): clamp exFAT volume-label length in f_getlabel() (CVE-2026-6687)
f_getlabel() extracts the exFAT volume label with a loop bounded by the on-disk
byte dj.dir[XDIR_NumLabel] (0-255):

    for (si = di = hs = 0; si < dj.dir[XDIR_NumLabel]; si++)
        wc = ld_16(dj.dir + XDIR_Label + si * 2);

The exFAT label field holds at most 11 UTF-16 units (22 bytes). A crafted
directory entry with a larger count both reads past the 22-byte label field and,
through put_utf(... &label[di], 4), writes past the end of the caller-provided
label buffer (the canonical API examples use small fixed stack buffers) -> stack
buffer overflow.

Clamp the character count to the exFAT maximum of 11 before the extraction loop.
Record the CVE in the component SBOM.

Note: f_getlabel() takes no destination-buffer size, so under UTF-8 output
(FF_LFN_UNICODE == 2) 11 units can still expand to up to 34 bytes; the clamp
downgrades this from attacker-unbounded to spec-bounded. ESP-IDF's VFS layer
does not call f_getlabel(); direct callers on untrusted media should size their
buffer accordingly. A complete fix requires an upstream size-aware API change.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:40:50 +02:00
Tomáš Rohlínek e6e7c9f4bc fix(storage/fatfs): guard dirty-cache refill against unsigned LBA wrap (CVE-2026-6685)
After a direct multi-sector disk_read()/disk_write(), FatFs decides whether the
cached sector overlaps the direct-I/O range with:

    fp->sect - sect < cc          (and the FF_FS_TINY variant fs->winsect - sect < cc)

`sect`, `fp->sect` and `fs->winsect` are unsigned LBA_t. On 32-bit LBA_t builds,
if the cached sector is below `sect`, the subtraction wraps to a huge value that
can still compare `< cc`, so the code computes a bogus large offset:

  - in f_write() it mis-copies from the direct write buffer (data corruption);
  - in f_read() it is worse: memcpy(rbuff + (wrapped_offset * SS), ...) is an
    out-of-bounds WRITE into the caller-supplied read buffer.

Add an explicit lower-bound check (fp->sect >= sect, resp. fs->winsect >= sect)
before the range test on both the read and write paths and both the FF_FS_TINY
and normal variants, so the condition is exactly "cached sector lies within
[sect, sect + cc)". Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:40:50 +02:00
Tomáš Rohlínek 895de2abee fix(storage/fatfs): reject empty exFAT cluster heap and guard divisor (CVE-2026-6683)
The FAT12/16/32 mount path rejects a zero cluster count, but the exFAT path
accepted NumClusters == 0. That yields fs->n_fatent == 2, and sync_fs() later
computes the "percent in use" field as:

    ... * 100 / (fs->n_fatent - 2)

which is a division by zero (n_fatent - 2 == 0) -> crash. On a device that
syncs during an update this can brick the unit.

Reject ncl == 0 at exFAT mount time, and add a defense-in-depth
`fs->n_fatent > 2` guard around the division in sync_fs() so the divisor can
never be zero even if some future path produces such a filesystem object.
Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:40:50 +02:00
Tomáš Rohlínek 388efbf2b7 fix(storage/fatfs): fix exFAT mount integer overflow (CVE-2026-6682)
The exFAT mount path validates that the media is large enough to hold the
declared cluster heap with:

    if (maxlba < (QWORD)fs->database + ncl * fs->csize) ...

`ncl` (DWORD, up to MAX_EXFAT) and `fs->csize` (WORD) are both promoted to
`unsigned int`, so `ncl * fs->csize` is evaluated in 32-bit arithmetic and can
wrap before the QWORD promotion of the sum. A crafted image with a large
NumClusters/SecPerClus can therefore make an undersized volume pass the "size
is large enough" check; subsequent cluster->sector math then addresses media
outside the actual device.

Promote the multiply to 64-bit ((QWORD)ncl * fs->csize). Apply the same
promotion to the bitmap-base computation ((LBA_t)fs->csize * (bcl - 2)), which
has the identical overflow shape. Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 14:40:50 +02:00
Tomáš Rohlínek a1695a475b fix(storage/fatfs): correct SBOM version to R0.16
The vendored FatFs sources are revision R0.16 (FF_DEFINED == 80386, per
components/fatfs/src/ff.h and ff.c) but the SBOM recorded R0.15. Correct the
recorded version so vulnerability tracking matches the actual sources.
2026-07-06 14:40:50 +02:00
Luo Xu d75f7448e5 fix(ble_mesh): re-check scan dev-found cb before scan-rsp invocation
(cherry picked from commit 9a3a767824)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:42 +08:00
Luo Xu 1b68511f89 fix(ble_mesh): comment out logs containing sensitive keys
(cherry picked from commit 781d6b2314)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:41 +08:00
Luo Xu 0e4e6ba61f fix(ble_mesh): validate PB-ADV start segment length
(cherry picked from commit 912ec8dc62)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:40 +08:00
Luo Xu 8d998f7fc1 fix(ble_mesh): Reset reassembly buffer at start of each transaction
The reassembly buffer must be reset to its origin at the beginning of every
transaction. prov_msg_recv() pulls the PDU type byte (advancing buf->data by
one) and nothing restores it between transactions. Without this reset,
buf->data drifts forward by one byte per received PDU, causing the segment-0
memcpy to write past the end of the statically allocated rx buffer
(PROV_RX_BUF_SIZE), and the XACT_SEG_DATA() offsets used for continuation
segments to be skewed by the accumulated drift.


(cherry picked from commit 2c4acaa2aa)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:39 +08:00
Luo Xu c92fb5c2cb fix(ble_mesh): fix DFD client message parsing and encoding bugs
Fix multiple wire-format and robustness issues in the DFD client
(dfd_cli.c):

- handle_capabilities: read oob_retrieval_supported as u8 instead of
  le32. The server encodes a single byte; le32 over-consumed 3 bytes
  of the URL scheme list and could over-read the buffer.
- handle_upload_status: extract upload_progress from bits 0-6 (& 0x7F)
  and upload_type from bit 7 (>> 7), matching the server encoding
  (progress | BIT(7)). The previous >>1 / &0x01 returned wrong values,
  mis-classified in-band vs OOB, and falsely rejected valid OOB
  messages with high progress.
- handle_dfd_status: correct the transfer-mode byte layout to
  trans_mode bits 0-1, update_policy bit 2, RFU bits 3-7 (previously
  read bits 6-7 / 5), and fix the RFU mask to 0xF8. Now matches the
  struct bitfield definition and the DFD server.
- handle_dfd_status: report status+phase and return early when
  buf->len == 0 (IDLE phase) instead of pulling 10 absent bytes.
- bt_mesh_dfd_cli_distribution_start: encode trans_mode/update_policy
  into bits 0-2 so the server decodes them correctly.
- handle_receiver_list: validate buf->len >= entries_cnt * 5 before
  the loop, and handle entries_cnt == 0 without relying on calloc(0).
- handle_receiver_status: pass the status value (not the whole union)
  to the %d log format, fixing undefined behavior.
- dfd_client_recv_status: drop the dead BLE_MESH_DFD_OP_CAPABILITIES_GET
  case (a client-send opcode) from the receive switch.
- bt_mesh_dfd_cli_receivers_add: widen msg_length to uint32_t to avoid
  uint16_t overflow that bypassed the PDU size guard; add a NULL check
  for the receivers array.
- bt_mesh_dfd_cli_distribution_upload_oob_start: return -EINVAL
  instead of -1 for consistency with the rest of the file.


(cherry picked from commit 43137475e1)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:38 +08:00
Luo Xu a475b0144e fix(ble_mesh): added max dfd srv count limit
(cherry picked from commit 781218cb62)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:37 +08:00
Luo Xu d5555a086c fix(ble_mesh): reject invalid chunk size
(cherry picked from commit 35cd10fbdf)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:37 +08:00
Luo Xu 5a57501543 fix(ble_mesh): fixed invalid disconnect handler wrote
(cherry picked from commit 52cfff707f)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:36 +08:00
Luo Xu 3821e89347 fix(ble_mesh): fixed BLE-Mesh NimBLE extended-adv reassembly buffer overflow on COMPLETE fragment
(cherry picked from commit 1b22467f63)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:34 +08:00
Luo Xu be19bf858d fix(ble_mesh): fixed BLE-Mesh GATTS read-callback error
(cherry picked from commit 00adfb3cbc)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-06 17:44:34 +08:00