Commit Graph
45936 Commits
Author SHA1 Message Date
morris ab634e7708 Merge branch 'docs/i2c_addr_description_v5.4' into 'release/v5.4'
docs(i2c): clarify 7-bit address usage (v5.4)

See merge request espressif/esp-idf!51092
2026-07-24 14:30:20 +08:00
zwx 6946fa80a0 feat(openthread): use ieee802154 event callback list instead of weak overrides 2026-07-24 14:23:50 +08:00
morris 15ce077144 Merge branch 'bugfix/ana_cmpr_macro_v5.4' into 'release/v5.4'
fix(ana_cmpr): Fix swapped POS/NEG cross interrupt masks on ESP32-C5/P4 (v5.4)

See merge request espressif/esp-idf!50801
2026-07-23 22:15:03 +08:00
Island 69ae551ac6 Merge branch 'fix/ble_hidd_remove_ccc_gating_v5.4' into 'release/v5.4'
fix(esp_hid/bluedroid): remove app-layer CCC gating in HID device (5.4)

See merge request espressif/esp-idf!51005
2026-07-23 19:26:13 +08:00
Tiago Medicci c064771d2e fix(ana_cmpr): Fix swapped POS/NEG cross interrupt masks on ESP32-P4 2026-07-23 17:15:03 +08:00
muhaidong 6becea20cb fix(coex): fix coex status get issue 2026-07-23 17:03:44 +08:00
Xu Si Yu c60989b27e fix(coex): move 15.4 register configuration to 15.4 init 2026-07-23 17:03:33 +08:00
Wang Meng Yang 15c2c05e96 Merge branch 'bugfix/bredr_critical_bugs_v5.4' into 'release/v5.4'
fix(bt/bluedroid): fixed issues from AI review in GAP, SPP, HID, L2CAP and HCI (v5.4)

See merge request espressif/esp-idf!51080
2026-07-23 16:44:30 +08:00
Island b0e440355d Merge branch 'fix/ble_log_compression_safety_v5.4' into 'release/v5.4'
fix(ble_log): fix unaligned access and buffer safety in log compression (5.4)

See merge request espressif/esp-idf!47929
2026-07-23 14:26:51 +08:00
Chen Chen 820df1b774 docs(i2c): clarify 7-bit address usage
Closes https://github.com/espressif/esp-idf/pull/18831
2026-07-23 09:13:50 +08:00
Jin Cheng 8359636930 change(bt/bluedroid): increased port low watermark of RFCOMM
When PORT_RX_BUF_LOW_WM is too low, RFCOMM replenishes credits only
after receiving a relatively large number of packets, which may cause
the peer to exhaust its credits and enter a stop-and-wait state.
Increase the low watermark to replenish credits more promptly and
reduce the likelihood of the peer stalling while waiting for additional
credits.
2026-07-23 08:09:59 +08:00
Jin Cheng b19ab411cb fix(bt/bluedroid): fixed issues from AI review in GAP, SPP, HID, L2CAP and HCI 2026-07-23 07:52:39 +08:00
Tomáš Rohlínek fc33b0dcde fix(storage/fatfs): fix FAT32 mount integer overflow (CVE-2026-6682)
The initial CVE-2026-6682 fix hardened the exFAT mount path, but the CVE
as reported by runZero is a FAT32 defect in mount_volume() and is
reachable in the default configuration (exFAT and 64-bit LBA disabled).
This corrects the fix.

Root cause: `fasize *= fs->n_fats` is a DWORD multiply with no overflow
guard. A crafted BPB_FATSz32 such as 0x80000001 with NumFATs=2 wraps
`fasize` to 0x00000002. The wrapped (too-small) FAT size places
`fs->database` inside the FAT region, so a forged directory entry yields
an attacker-controlled `finfo.fsize`; a caller using it as a read length
overflows its buffer with attacker-controlled bytes (CVSS 7.6).

Fix: reject per-FAT and reserved+FAT+root system-area sizes that overflow
DWORD before they are used to derive the data-area base. The exFAT
cluster-heap/bitmap 64-bit promotions are retained as defense-in-depth
and relabeled (they are not CVE-2026-6682). SBOM reason updated.
2026-07-22 20:34:55 +08:00
Tomáš Rohlínek e9d404254b fix(storage/fatfs): record non-applicable runZero 2026 CVEs in SBOM
Document the three runZero "Seven FatFs bugs" CVEs that require no source change
in this component, so vulnerability scanners have their disposition:

  - CVE-2026-6684: GPT partition-scan loop DoS. Already fixed upstream in R0.16,
    where test_gpt_header() caps the partition-entry count at 128.
  - CVE-2026-6686: read of uninitialized clusters after f_lseek() past EOF.
    Longstanding, behavioral; not a memory-safety defect and zero-filling every
    extended cluster is prohibitively costly on flash.
  - CVE-2026-6688: long-filename overflow in downstream callers. Not exposed in
    ESP-IDF; vfs_fat.c uses bounded copies and fname is bounded by FF_MAX_LFN.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-22 20:34:55 +08:00
Tomáš Rohlínek 1364005a2e fix(storage/fatfs): clamp exFAT volume-label length in f_getlabel() (CVE-2026-6687)
f_getlabel() extracts the exFAT volume label with a loop bounded by the on-disk
byte dj.dir[XDIR_NumLabel] (0-255):

    for (si = di = hs = 0; si < dj.dir[XDIR_NumLabel]; si++)
        wc = ld_16(dj.dir + XDIR_Label + si * 2);

The exFAT label field holds at most 11 UTF-16 units (22 bytes). A crafted
directory entry with a larger count both reads past the 22-byte label field and,
through put_utf(... &label[di], 4), writes past the end of the caller-provided
label buffer (the canonical API examples use small fixed stack buffers) -> stack
buffer overflow.

Clamp the character count to the exFAT maximum of 11 before the extraction loop.
Record the CVE in the component SBOM.

Note: f_getlabel() takes no destination-buffer size, so under UTF-8 output
(FF_LFN_UNICODE == 2) 11 units can still expand to up to 34 bytes; the clamp
downgrades this from attacker-unbounded to spec-bounded. ESP-IDF's VFS layer
does not call f_getlabel(); direct callers on untrusted media should size their
buffer accordingly. A complete fix requires an upstream size-aware API change.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-22 20:34:55 +08:00
Tomáš Rohlínek 703cb336b1 fix(storage/fatfs): guard dirty-cache refill against unsigned LBA wrap (CVE-2026-6685)
After a direct multi-sector disk_read()/disk_write(), FatFs decides whether the
cached sector overlaps the direct-I/O range with:

    fp->sect - sect < cc          (and the FF_FS_TINY variant fs->winsect - sect < cc)

`sect`, `fp->sect` and `fs->winsect` are unsigned LBA_t. On 32-bit LBA_t builds,
if the cached sector is below `sect`, the subtraction wraps to a huge value that
can still compare `< cc`, so the code computes a bogus large offset:

  - in f_write() it mis-copies from the direct write buffer (data corruption);
  - in f_read() it is worse: memcpy(rbuff + (wrapped_offset * SS), ...) is an
    out-of-bounds WRITE into the caller-supplied read buffer.

Add an explicit lower-bound check (fp->sect >= sect, resp. fs->winsect >= sect)
before the range test on both the read and write paths and both the FF_FS_TINY
and normal variants, so the condition is exactly "cached sector lies within
[sect, sect + cc)". Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-22 20:34:55 +08:00
Tomáš Rohlínek df3df94c58 fix(storage/fatfs): reject empty exFAT cluster heap (CVE-2026-6683)
CVE-2026-6683 is an exFAT divide-by-zero: with NumClusters == 0 the filesystem
object has fs->n_fatent == 2, and the exFAT "percent in use" update in sync_fs()
computes ... * 100 / (fs->n_fatent - 2) -> division by zero.

That vulnerable exFAT PercInUse sync path was introduced in FatFs R0.16 and is
NOT present in this R0.15 release, so the divide-by-zero itself is not reachable
here. As defense-in-depth (and to keep parity with newer releases) reject an
empty exFAT cluster heap at mount time, which is a malformed volume regardless.

Record the CVE disposition in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-22 20:34:55 +08:00
Tomáš Rohlínek b5c012dc19 fix(storage/fatfs): fix exFAT mount integer overflow (CVE-2026-6682)
The exFAT mount path validates that the media is large enough to hold the
declared cluster heap with:

    if (maxlba < (QWORD)fs->database + ncl * fs->csize) ...

`ncl` (DWORD, up to MAX_EXFAT) and `fs->csize` (WORD) are both promoted to
`unsigned int`, so `ncl * fs->csize` is evaluated in 32-bit arithmetic and can
wrap before the QWORD promotion of the sum. A crafted image with a large
NumClusters/SecPerClus can therefore make an undersized volume pass the "size
is large enough" check; subsequent cluster->sector math then addresses media
outside the actual device.

Promote the multiply to 64-bit ((QWORD)ncl * fs->csize). Apply the same
promotion to the bitmap-base computation ((LBA_t)fs->csize * (bcl - 2)), which
has the identical overflow shape. Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-22 20:34:55 +08:00
Jack c0466739ba fix(phy): removed all librfate logic from cmake 2026-07-22 20:04:28 +08:00
morris 2b49bba8a8 Merge branch 'feat/i2s_duplex_update_v5.4' into 'release/v5.4'
feat(i2s): allow full duplex mode in less strict condition (v5.4)

See merge request espressif/esp-idf!50868
2026-07-22 18:26:50 +08:00
Wang Meng Yang 6fa5210202 Merge branch 'bugfix/idf_ci_example_avrcp_v5.4' into 'release/v5.4'
fix(bt/example): Add log in the failure path for avrcp_ct_metadata example (v5.4)

See merge request espressif/esp-idf!51061
2026-07-22 16:05:13 +08:00
yangfeng 66e234ebed fix(bt/example): Add log in the failure path for avrcp_ct_metadata example 2026-07-22 15:36:43 +08:00
Astha Verma e7321c0ce0 fix(nimble): Handle Read Remote Supported Features failure correctly 2026-07-22 12:20:07 +05:30
Wang Meng Yang 4d44115e31 Merge branch 'bugfix/hid_host_oob_read_v5.4' into 'release/v5.4'
fix(bt/bluedroid): fixed possible 1-byte OOB read in bta_hh_ctrl_dat_act (v5.4)

See merge request espressif/esp-idf!50974
2026-07-22 14:10:28 +08:00
Island 472d73d74c Merge branch 'fix/ble-log-store-access-fault_v5.4' into 'release/v5.4'
fix: Ensure BLE Log Global Variables in Internal RAM (5.4)

See merge request espressif/esp-idf!51034
2026-07-22 14:02:47 +08:00
zhuanghang 2e91163d02 feat(phy): update phy lib for esp32s31 & esp32c6 for track 2026-07-22 14:01:50 +08:00
Mahavir Jain 19c8b065db Merge branch 'feat/mbedtls_update_3.6.7_v5.4' into 'release/v5.4'
feat(mbedtls): update to version 3.6.7 (v5.4)

See merge request espressif/esp-idf!50658
2026-07-22 09:38:55 +05:30
luoxu 1b4a951a83 fix(bt): reorder test imports to satisfy pre-commit 2026-07-21 21:44:26 +08:00
Martin Vychodil 97801546aa Merge branch 'fix/sdmmc_cmd_err_switch_case_handling_v5.4' into 'release/v5.4'
fix(sdmmc): sdmmc_cmd.c fixed error handling in certain if and switch statements (v5.4)

See merge request espressif/esp-idf!50685
2026-07-21 20:55:46 +08:00
Zhou Xiao e6f43ca6c6 fix(bt): keep BLE log ISR state in internal RAM
(cherry picked from commit 2fa434eb50)

Co-authored-by: Zhou Xiao <zhouxiao@espressif.com>
2026-07-21 19:44:14 +08:00
Euripedes Rocha 9f2a5a51ff Merge branch 'fix/sec-1137-br-glue-double-free_v5.4' into 'release/v5.4'
fix(esp_netif): harden br_glue instance-handler cleanup against double-free (SEC-1137) (v5.4)

See merge request espressif/esp-idf!50645
2026-07-21 10:41:53 +02:00
Ashish Sharma cfae960f2e feat(mbedtls): add option to choose constant-time prime generation 2026-07-21 16:03:27 +08:00
Ashish Sharma 1646e69781 feat(mbedtls): update to version 3.6.7 2026-07-21 15:47:46 +08:00
luoxu 4cab74130e fix(ble_log): use typing.Optional/List for Python 3.9 compatibility 2026-07-21 14:12:42 +08:00
luoxu 0e2015cf8f fix(ble_log): fix size_info nibble misalignment for last odd-count arg 2026-07-21 14:12:42 +08:00
luoxu ad114e99ab fix(ble_log): fix unaligned access and buffer safety in log compression 2026-07-21 14:12:42 +08:00
Luo Xu be5454fe34 test(ble): add comprehensive test suite for log compression
(cherry picked from commit 58121d2540)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-21 14:12:42 +08:00
Luo Xu 738a99800b fix(ble): replace hardcoded tuple indices with FormatToken NamedTuple
(cherry picked from commit b7760a77e4)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-21 14:12:42 +08:00
Wang Meng Yang a8134b4456 Merge branch 'bugfix/a2dp_sbc_v5.4' into 'release/v5.4'
fix(bt): Fix the pointer sbc_start_frame is not initialized(v5.4)

See merge request espressif/esp-idf!50958
2026-07-21 13:36:43 +08:00
Chen Chen 2f9d144cbe refactor(i2s): make the slot_bit_width checks unique 2026-07-21 11:09:53 +08:00
Zhang Hai Peng 0b76a22522 change(ble/bluedroid): disable host trace logs when BLE Log host is off
Default all Bluedroid layer trace levels to NONE when BLE async log
is enabled without BLE_LOG_HOST_LOG.


(cherry picked from commit 1f8f935e3f)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-21 10:44:07 +08:00
Zhang Hai Peng cc6fd5167b fix(esp_hid/bluedroid): remove app-layer CCC gating in HID device
Do not check CCCD before sending notify in battery_set,
input_set and feature_set.


(cherry picked from commit 81bbcaca4e)

Co-authored-by: zhanghaipeng <zhanghaipeng@espressif.com>
2026-07-21 10:43:53 +08:00
morris fd011d7d7e Merge branch 'fix/fix_i2s_i80_color_size_check_v5.4' into 'release/v5.4'
fix(lcd): add color size check for i80 and boundary check for rgb (v5.4)

See merge request espressif/esp-idf!50966
2026-07-21 10:26:13 +08:00
Island 1d545e6618 Merge branch 'feat/ble_log_compression_module_cfg_update_v5.4' into 'release/v5.4'
Feat/ble log compression module cfg update (5.4)

See merge request espressif/esp-idf!49873
2026-07-20 21:37:56 +08:00
Chen Jichang 9f68a52bd3 fix(lcd): add color size check for i80 and boundary check for rgb 2026-07-20 17:42:46 +08:00
Alexey Gerenkov a65b5216c6 Merge branch 'feature/update-openocd-to-v0.12.0-esp32-20260703_v5.4' into 'release/v5.4'
feat(tools): update openocd version to v0.12.0-esp32-20260703 (v5.4)

See merge request espressif/esp-idf!50505
2026-07-20 17:20:29 +08:00
Alexey Gerenkov 166e2a075e Merge branch 'fix/lp_core_noreset_under_debug_option_v5.4' into 'release/v5.4'
fix(lp_core): fix build for CONFIG_ULP_NORESET_UNDER_DEBUG=n (v5.4)

See merge request espressif/esp-idf!49870
2026-07-20 17:11:03 +08:00
Jin Cheng 888cd3cfa9 fix(bt/bluedroid): fixed possible 1-byte OOB read in bta_hh_ctrl_dat_act
Closes SEC-786
2026-07-20 16:38:11 +08:00
morris 434942d91d Merge branch 'fix/fix_image_header_check_v5.4' into 'release/v5.4'
image header: fixed image header segment count check (v5.4)

See merge request espressif/esp-idf!50937
2026-07-20 15:34:36 +08:00
Jiang Jiang Jian ecbdbf98b5 Merge branch 'fix/blacklist_flag_correction_v5.4' into 'release/v5.4'
fix(wifi): Correct blacklist flag(v5.4)

See merge request espressif/esp-idf!50921
2026-07-20 15:22:58 +08:00