Commit Graph
37428 Commits
Author SHA1 Message Date
Ashish Sharma aebc7fa691 fix(protocomm): fix response leaks and stale key IDs on error paths 2026-07-15 15:46:58 +08:00
yi chen 1fa38c2f25 Avoid re-destroying a released Security1 key
The second cipher-update failure destroys the volatile symmetric key but left its identifier cached in session state. Clear it immediately so sec1_close_session() cannot try to destroy the same key again.

Constraint: Follow-up to maintainer review on espressif/esp-idf#18813

Confidence: high

Scope-risk: narrow

Tested: security1.c cross-compiled for ESP32 with Xtensa GCC 14.2.0; test_security1.c compiled with the test app flags; git diff --check

Not-tested: Full master test-app link or on-target execution; local IDF 5.4.3 differs from the PR's master baseline in PSA ABI and Mbed TLS headers
2026-07-14 16:08:42 +08:00
yi chen 641c2f7c53 fix(protocomm): free response buffers on 2nd psa_cipher_update failure
In handle_session_command1(), if the second psa_cipher_update()
call (encrypting the device verify data to send back to the client)
fails, the error path only frees the outbuf ciphertext buffer. The
out (Sec1Payload) and out_resp (SessionResp1) structures allocated
just before it are never freed, and neither the cipher operation
(cur_session->ctx_aes) nor the imported key (key_id) are released.

The caller (sec1_req_handler(), via sec1_session_setup()) returns
immediately on a non-ESP_OK result without doing any cleanup of its
own here - sec1_session_setup_cleanup() only runs on the success
path, once resp->sec1 has actually been assigned - so nothing else
ever frees these on this path.

Add psa_cipher_abort()/psa_destroy_key() and free() for out/out_resp,
matching the cleanup already done for every other failure branch
earlier in this same function.

Fixes #18804

Signed-off-by: yi chen <94xhn1@gmail.com>
2026-07-10 06:53:44 +08:00
Li Shuai f70ea602fe Merge branch 'feat/idfgh-17859' into 'master'
add kconfig option for REGDMA sleep clock ICG

Closes IDFGH-17859

See merge request espressif/esp-idf!50228
2026-07-07 21:50:10 +08:00
Wang Meng Yang 78fea40c2e Merge branch 'fix/tx_power_validate' into 'master'
fix(bt): validate BR/EDR TX power against chip-supported range

See merge request espressif/esp-idf!50072
2026-07-07 20:38:45 +08:00
Jiang Jiang Jian 1605930498 Merge branch 'bugfix/fix_offchan_rx_fail_when_spiram_enabled' into 'master'
fix(wifi): fixed the offchan tx fail when SPIRAM_TRY_ALLOCATE_WIFI_LWIP enabled

Closes WIFI-7402

See merge request espressif/esp-idf!50194
2026-07-07 19:34:43 +08:00
Mahavir Jain 05250d7dd1 Merge branch 'feat/enable_cross_signed_cert_suppport_default' into 'master'
feat(mbedtls): enable cross signed certificate verification support by default

See merge request espressif/esp-idf!49905
2026-07-07 14:47:37 +05:30
Hu Rui 484f5f3426 Merge branch 'feat/usj_custom_intr_prior' into 'master'
feat(usj): support set interrupt priority

Closes IDF-7961

See merge request espressif/esp-idf!50376
2026-07-07 16:35:06 +08:00
chenqingqing 9fbebf293d fix(bt): clarify BR/EDR TX power behavior in menuconfig help 2026-07-07 15:39:26 +08:00
zhangyanjiao cf695709f1 fix(wifi): fixed the offchan tx fail when SPIRAM_TRY_ALLOCATE_WIFI_LWIP enabled 2026-07-07 15:31:00 +08:00
C.S.M e36835fe0c Merge branch 'fix/jpeg_enc_encrypt' into 'master'
fix(jpeg): Jpeg can encode and decode in encryption situation

Closes IDF-15061

See merge request espressif/esp-idf!50063
2026-07-07 13:36:20 +08:00
Mahavir Jain cf322e283f Merge branch 'fix/bootloader_anti_rollback_konfig' into 'master'
fix(bootloader): Hide bootloader anti-rollback Kconfig where not supported

See merge request espressif/esp-idf!50413
2026-07-07 10:40:21 +05:30
Nachiket Kukade 87ed41697c Merge branch 'fix/pbkdf2_sha256_mbedtls4_guard' into 'master'
fix(wpa_supplicant): guard pbkdf2_sha256 for PSA-provided SHA-256

See merge request espressif/esp-idf!50395
2026-07-07 12:25:47 +08:00
Meet Patel 2fd3ccbb19 Merge branch 'test/idf-additions-coverage' into 'master'
test(freertos): expand IDF additions test coverage

See merge request espressif/esp-idf!50303
2026-07-07 09:44:56 +05:30
Song Ruo Jing e00086907a Merge branch 'bugfix/uart_sw_flow_ctrl_xoff_char' into 'master'
fix(uart): fix uart sw flow ctrl XOFF char write to wrong reg on ESP32C6

Closes IDFGH-17885

See merge request espressif/esp-idf!50296
2026-07-07 12:11:30 +08:00
C.S.M 048b4dde0c feat(psram): Add unencrypted region for psram for esp32s31 2026-07-07 10:42:45 +08:00
C.S.M fbdf6d7427 fix(jpeg): JPEG can encode and decode in encryption situation 2026-07-07 10:42:45 +08:00
morris fbe6d9005a Merge branch 'refactor/move_regdma_entry_config_to_driver_layer_sdm' into 'master'
refactor(sdm): move sleep retention config into driver layer

See merge request espressif/esp-idf!50364
2026-07-07 00:07:33 +08:00
Tomas Rohlinek 5fde421955 Merge branch 'fix/fatfs_vulnerabilities' into 'master'
fix(fatfs): harden against runZero 2026 FatFs bugs

See merge request espressif/esp-idf!50362
2026-07-06 15:20:15 +02:00
Song Ruo Jing f324ddd849 ci(uart): enable test for esp32h4 2026-07-06 20:53:28 +08:00
Song Ruo Jing a5ff63830e fix(uart): fix uart sw flow ctrl XOFF char write to wrong reg on ESP32C6
Add software flow control test case

Introduced in e6ef4d1791

Closes https://github.com/espressif/esp-idf/issues/18779
2026-07-06 20:49:56 +08:00
chenqingqing e42038bad2 fix(bt): validate BR/EDR TX power against chip-supported range
The TX power range configurable in menuconfig only describes the maximum possible range.
Add a function to report the real range, and validate the configured BR/EDR TX power values during conroller init.
2026-07-06 20:45:21 +08:00
Tomáš Rohlínek 5716f444d4 fix(storage/fatfs): record non-applicable runZero 2026 CVEs in SBOM
Document the three runZero "Seven FatFs bugs" CVEs that require no source change
in this component, so vulnerability scanners have their disposition:

  - CVE-2026-6684: GPT partition-scan loop DoS. Already fixed upstream in R0.16,
    where test_gpt_header() caps the partition-entry count at 128.
  - CVE-2026-6686: read of uninitialized clusters after f_lseek() past EOF.
    Longstanding, behavioral; not a memory-safety defect and zero-filling every
    extended cluster is prohibitively costly on flash.
  - CVE-2026-6688: long-filename overflow in downstream callers. Not exposed in
    ESP-IDF; vfs_fat.c uses bounded copies and fname is bounded by FF_MAX_LFN.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 13:39:24 +02:00
Tomáš Rohlínek 838ea02c56 fix(storage/fatfs): clamp exFAT volume-label length in f_getlabel() (CVE-2026-6687)
f_getlabel() extracts the exFAT volume label with a loop bounded by the on-disk
byte dj.dir[XDIR_NumLabel] (0-255):

    for (si = di = hs = 0; si < dj.dir[XDIR_NumLabel]; si++)
        wc = ld_16(dj.dir + XDIR_Label + si * 2);

The exFAT label field holds at most 11 UTF-16 units (22 bytes). A crafted
directory entry with a larger count both reads past the 22-byte label field and,
through put_utf(... &label[di], 4), writes past the end of the caller-provided
label buffer (the canonical API examples use small fixed stack buffers) -> stack
buffer overflow.

Clamp the character count to the exFAT maximum of 11 before the extraction loop.
Record the CVE in the component SBOM.

Note: f_getlabel() takes no destination-buffer size, so under UTF-8 output
(FF_LFN_UNICODE == 2) 11 units can still expand to up to 34 bytes; the clamp
downgrades this from attacker-unbounded to spec-bounded. ESP-IDF's VFS layer
does not call f_getlabel(); direct callers on untrusted media should size their
buffer accordingly. A complete fix requires an upstream size-aware API change.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 13:38:59 +02:00
Tomáš Rohlínek 98416b7e13 fix(storage/fatfs): guard dirty-cache refill against unsigned LBA wrap (CVE-2026-6685)
After a direct multi-sector disk_read()/disk_write(), FatFs decides whether the
cached sector overlaps the direct-I/O range with:

    fp->sect - sect < cc          (and the FF_FS_TINY variant fs->winsect - sect < cc)

`sect`, `fp->sect` and `fs->winsect` are unsigned LBA_t. On 32-bit LBA_t builds,
if the cached sector is below `sect`, the subtraction wraps to a huge value that
can still compare `< cc`, so the code computes a bogus large offset:

  - in f_write() it mis-copies from the direct write buffer (data corruption);
  - in f_read() it is worse: memcpy(rbuff + (wrapped_offset * SS), ...) is an
    out-of-bounds WRITE into the caller-supplied read buffer.

Add an explicit lower-bound check (fp->sect >= sect, resp. fs->winsect >= sect)
before the range test on both the read and write paths and both the FF_FS_TINY
and normal variants, so the condition is exactly "cached sector lies within
[sect, sect + cc)". Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 13:38:29 +02:00
Tomáš Rohlínek 7d73545564 fix(storage/fatfs): reject empty exFAT cluster heap and guard divisor (CVE-2026-6683)
The FAT12/16/32 mount path rejects a zero cluster count, but the exFAT path
accepted NumClusters == 0. That yields fs->n_fatent == 2, and sync_fs() later
computes the "percent in use" field as:

    ... * 100 / (fs->n_fatent - 2)

which is a division by zero (n_fatent - 2 == 0) -> crash. On a device that
syncs during an update this can brick the unit.

Reject ncl == 0 at exFAT mount time, and add a defense-in-depth
`fs->n_fatent > 2` guard around the division in sync_fs() so the divisor can
never be zero even if some future path produces such a filesystem object.
Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 13:37:59 +02:00
Tomáš Rohlínek 81ec08b949 fix(storage/fatfs): fix exFAT mount integer overflow (CVE-2026-6682)
The exFAT mount path validates that the media is large enough to hold the
declared cluster heap with:

    if (maxlba < (QWORD)fs->database + ncl * fs->csize) ...

`ncl` (DWORD, up to MAX_EXFAT) and `fs->csize` (WORD) are both promoted to
`unsigned int`, so `ncl * fs->csize` is evaluated in 32-bit arithmetic and can
wrap before the QWORD promotion of the sum. A crafted image with a large
NumClusters/SecPerClus can therefore make an undersized volume pass the "size
is large enough" check; subsequent cluster->sector math then addresses media
outside the actual device.

Promote the multiply to 64-bit ((QWORD)ncl * fs->csize). Apply the same
promotion to the bitmap-base computation ((LBA_t)fs->csize * (bcl - 2)), which
has the identical overflow shape. Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 13:37:28 +02:00
Tomáš Rohlínek ae0fad3bac fix(storage/fatfs): correct SBOM version to R0.16
The vendored FatFs sources are revision R0.16 (FF_DEFINED == 80386, per
components/fatfs/src/ff.h and ff.c) but the SBOM recorded R0.15. Correct the
recorded version so vulnerability tracking matches the actual sources.
2026-07-06 13:36:59 +02:00
morris 18f50fefa9 Merge branch 'feat/esp_macro_align_up_down' into 'master'
refactor(esp_common): centralize ALIGN_UP/ALIGN_DOWN into esp_macros.h

See merge request espressif/esp-idf!50335
2026-07-06 19:09:14 +08:00
Hu Rui 048630bd9a feat(usj): support set interrupt priority 2026-07-06 19:08:13 +08:00
Konstantin Kondrashov d65c091ad8 fix(bootloader): Hide bootloader anti-rollback Kconfig where not supported 2026-07-06 13:58:39 +03:00
Nilesh Kale 4eaa03abf5 Merge branch 'feat/enable_aes_gcm_support_for_esp32s31' into 'master'
feat: enable AES GCM support for ESP32-S31

Closes IDF-15529

See merge request espressif/esp-idf!47564
2026-07-06 17:35:39 +08:00
Martin Vychodil ee0099188c Merge branch 'fix/vfs_fatfs_test_stale_partition' into 'master'
test(vfs): reformat WL FATFS in setup to avoid stale-partition flakes

See merge request espressif/esp-idf!50393
2026-07-06 17:31:59 +08:00
Sarvesh Bodakhe 5bf61777b6 fix(wpa_supplicant): guard pbkdf2_sha256 for PSA-provided SHA-256
mbedtls 4.x is PSA-first: CONFIG_MBEDTLS_SHA256_C now maps to
PSA_WANT_ALG_SHA_256, and on ESP targets the hardware SHA accelerator
serves SHA-256 through PSA, leaving the legacy MBEDTLS_SHA256_C builtin
macro undefined. The inner guard on pbkdf2_sha256 was gating on bare
MBEDTLS_SHA256_C, so the function was compiled out and NAN ND-PMK
derivation (nan_derive_nd_pmk_from_passphrase) failed to link.

Guard on (MBEDTLS_SHA256_C || PSA_WANT_ALG_SHA_256) to match the idiom
already used elsewhere in the supplicant mbedtls port (tls_mbedtls.c),
covering both the legacy builtin and PSA-provided SHA-256.
2026-07-06 14:41:23 +05:30
Aditya Patwardhan 5ee87f7b2c Merge branch 'fix/nvs-encrypted-partition-destructor-zeroize' into 'master'
fix(nvs_flash): zeroize XTS contexts when encrypted partition is destroyed

See merge request espressif/esp-idf!47585
2026-07-06 14:29:27 +05:30
Martin VychodilandCursor 99f87d8ac9 test(vfs): reformat WL FATFS in setup to avoid stale-partition flakes
Reformat the test partition before each mount so those tests always start from
a known-empty filesystem.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-06 10:57:30 +02:00
Mahavir Jain 7eb664f61f Merge branch 'feat/update_documentation_and_cleanup_for_esp32h4' into 'master'
Feat/update documentation and cleanup for esp32h4

See merge request espressif/esp-idf!49426
2026-07-06 14:05:31 +05:30
Chen Ji Chang b09ea896b6 Merge branch 'fix/fix_async_color_convert_csc' into 'master'
fix(dma2d): fix async color convert csc check

See merge request espressif/esp-idf!50229
2026-07-06 16:10:10 +08:00
Ashish Sharma 5ea5256b96 feat(mbedtls): enable cross signed certificate verification support by default 2026-07-06 15:34:51 +08:00
Jiang Jiang Jian 309b3e82ec Merge branch 'fix/ble_mesh_disable_adv_pkt_discard_log' into 'master'
fix(ble_mesh): Disable warning logging when advertising packets are discarded

Closes BLERP-2945

See merge request espressif/esp-idf!50146
2026-07-06 15:13:06 +08:00
morris 4704a99af3 refactor(sdm): move sleep retention config into driver layer
Move SDM regdma retention descriptors out of esp_hal_gpio and into
per-target
esp_driver_sdm sources so the driver owns its backup scope and restore
flow.
2026-07-06 15:09:37 +08:00
Jiang Jiang Jian 9126adadb9 Merge branch 'fix/ble_mesh_fixed_issues' into 'master'
Resolve NVIDIA-reported BLE mesh stack issues

Closes SEC-1116, SEC-1069, SEC-761, SEC-1068, SEC-1130, and SEC-1185

See merge request espressif/esp-idf!50176
2026-07-06 15:09:30 +08:00
Mahavir Jain 442cc028b5 Merge branch 'fix/fix_esp_http_client_cross_origin_credentials' into 'master'
fix(esp_http_client): strip Authorization header on cross-origin redirect

Closes SEC-228 and SEC-049

See merge request espressif/esp-idf!48820
2026-07-06 12:20:51 +05:30
nilesh.kale ec6921b9df feat: enable AES GCM support for ESP32-S31 2026-07-06 11:51:05 +05:30
Ashish Sharma f7b8db2f2f feat(espcoredump): migrate to esp sha256 implementation from mbedtls sha256 2026-07-06 11:11:12 +05:30
morris 651d6a283f refactor(esp_common): centralize ALIGN_UP/ALIGN_DOWN into esp_macros.h
Remove ~50 duplicate local definitions of ALIGN_UP/ALIGN_DOWN/ALIGN_UP_BY/
ALIGN_DOWN_BY across the codebase and replace them with canonical
ESP_ALIGN_UP/ESP_ALIGN_DOWN from esp_macros.h.
2026-07-06 13:36:06 +08:00
Meet Patel d0e018cf6b test(freertos): expand IDF additions test coverage
Improve coverage of idf_additions.h task utility APIs and correct
WithCaps delete usage in existing tests to avoid heap leaks.
2026-07-06 10:45:53 +05:30
Ashish Sharma 7d9f061cc1 fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer 2026-07-06 10:38:10 +05:30
Aditya Patwardhan 2468defbff Merge branch 'feat/update_documentation_and_cleanup_for_s31' into 'master'
enable tests and cleanup JIRA references for s31

Closes IDF-14629 and IDF-14628

See merge request espressif/esp-idf!49273
2026-07-06 10:31:47 +05:30
Chen Jichang 5123e1c634 fix(dma2d): fix async color convert csc check 2026-07-06 12:43:35 +08:00