Commit Graph
35328 Commits
Author SHA1 Message Date
Jin Cheng 0285bb55d2 fix(bt/bluedroid): added buffer length check for HID Device data indication 2026-06-12 18:32:39 +08:00
Jin Cheng a7aca1c1a3 fix(bt/bluedroid): added validation for all SMP BR opcode lengths in smp_br_data_received 2026-06-12 18:32:39 +08:00
Jin Cheng 043bad5c30 fix(bt/bluedroid): fixed CTKD link key authentication downgrade in SC-Only mode 2026-06-12 18:32:39 +08:00
Jin Cheng 129ce07ece fix(bt/bluedroid): added buffer length check for HID host data indication 2026-06-12 18:32:39 +08:00
Jin Cheng 9a6d04f65e fix(bt/bluedroid): added buffer length check for L2CAP related functions 2026-06-12 18:32:39 +08:00
surengab 4bdf427ca1 fix(ws_transport): reject oversized 64-bit WebSocket payload length 2026-06-12 11:59:58 +02:00
Laukik Hase 39a4cf5e56 feat(esp_tee): Clear out all sensitive buffers explicitly after TEE crypto operations 2026-06-12 10:04:07 +05:30
Laukik Hase 61b88163be ci(esp_tee): Add test-case for verifying the TEE Secure Storage encryption 2026-06-12 10:04:07 +05:30
Laukik Hase 93466c1fd3 feat(esp_tee): Add some required fields in the attestation token
- Chip ID from the ROM
- Device MAC address from eFuse BLK1
- Device Optional Unique ID from eFuse BLK2
2026-06-12 10:04:06 +05:30
Laukik Hase 6bd173b806 ci(esp_tee): Fix TEE test-suite failures with Secure Boot enabled 2026-06-12 10:04:04 +05:30
Laukik Hase f37a2cd35b feat(esp_tee): Remove unused components from the PSA Crypto library 2026-06-12 10:03:03 +05:30
Laukik Hase 140e1ae1f3 ci(esp_tee): Removed common_components dependency from ESP-TEE test-apps 2026-06-12 10:03:02 +05:30
Zhou Xiao 638cd4c1bd change(ble): [AUTO_MR] Update lib_esp32c2 to 750d4902
(cherry picked from commit 897f3b2af1)

Co-authored-by: Zhou Xiao <zhouxiao@espressif.com>
2026-06-12 12:14:38 +08:00
Aditya Patwardhan 839352f836 Merge branch 'fix/disable_secure_boot_v2_ecdsa_v6.0' into 'release/v6.0'
Fix/disable secure boot v2 ecdsa (v6.0)

See merge request espressif/esp-idf!49470
2026-06-11 07:48:52 +05:30
morris 970c2f83c3 Merge branch 'fix/jpeg_cve_fix_v6.0' into 'release/v6.0'
fix(jpeg_decoder): Add some strict check to avoid bad picture attack (backport v6.0)

See merge request espressif/esp-idf!49254
2026-06-11 10:13:09 +08:00
JiangGuangMingandCursor a90989cd6f feat(usb): add usb wakeup from light sleep example
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-11 09:24:04 +08:00
JiangGuangMingandCursor 6b3f1f077f feat(esp_hal_usb): add usb suspend wakeup status in ll layer
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-11 09:13:20 +08:00
JiangGuangMingandCursor e89a04d89e feat(sleep/usb): support usb as wakeup source from light sleep
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-11 09:13:20 +08:00
Marius Vikhammer 4dd862314d fix(ulp): fixes potential race-condition for lp-timer wakeup with lp-core
Reconfigure wakeup time before enabling the wakeup source to avoid
a wakeup from potentially stale values.

Closes https://github.com/espressif/esp-idf/issues/17009
2026-06-11 09:02:28 +08:00
Aditya Patwardhan 94be07050f change(secure_boot): mark ECDSA based Secure Boot V2 as insecure on affected SoCs
ECDSA based Secure Boot V2 is not functional for certain input vectors on
ESP32-C5/C61/H2/P4 and on the preview targets ESP32-H4/H21. RSA based Secure
Boot V2 is the recommended scheme where the SoC supports it. This issue will be
fixed in a future hardware ECO revision; more details will be shared through the
hardware errata document.

A new hidden Kconfig option SECURE_BOOT_V2_ECDSA_INSECURE marks the affected
mass-production SoCs (ESP32-C5/C61/H2/P4). On these SoCs, when hardware Secure
Boot V2 is enabled, the ECDSA (V2) signing scheme is no longer offered by
default; it must be turned on explicitly via SECURE_BOOT_V2_FORCE_ENABLE_ECDSA
under "Allow potentially insecure options" (CONFIG_SECURE_BOOT_INSECURE). App
signing without hardware Secure Boot is not affected. Note that ESP32-C61 has no
RSA based Secure Boot V2, so it has no Secure Boot scheme enabled by default.

The preview targets ESP32-H4 and ESP32-H21 mark ECDSA Secure Boot V2 as not
supported in their SoC capabilities instead of using the option above. As
ESP32-H4 has no other Secure Boot V2 scheme, Secure Boot is disabled entirely on
it; ESP32-H21 retains RSA based Secure Boot V2.

The security documentation keeps the ECDSA Secure Boot V2 content visible and
adds a warning describing the limitation (including that ECDSA Secure Boot V2 on
ESP32-C61 is not recommended for production). CI apps that exercise ECDSA Secure
Boot V2 on the affected SoCs set CONFIG_SECURE_BOOT_V2_FORCE_ENABLE_ECDSA
accordingly.
2026-06-10 18:06:48 +05:30
Chen Jichang a82f0d2bc3 fix(rgb_lcd): fix gdma link switch not take effect 2026-06-10 20:26:01 +08:00
Zhi Wei Jian b55f972546 fix(bt): fix BTC task and BLE mesh bluedroid adapter
(cherry picked from commit 678fb93245)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:54:01 +08:00
Zhi Wei Jian 848bdc0301 fix(ble/bluedroid): fix HCI command and BTU robustness
(cherry picked from commit c9d13aaf64)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:54:00 +08:00
Zhi Wei Jian cebf129df8 fix(ble/bluedroid): fix CTE and ISO API validation
(cherry picked from commit 0c3c894b7d)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:54:00 +08:00
Zhi Wei Jian b60fe364f0 fix(ble/bluedroid): fix GATT server lifecycle and callbacks
(cherry picked from commit 54a1e31916)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:54:00 +08:00
Zhi Wei Jian 7e97000e5c fix(ble/bluedroid): fix GATT client API parameter validation
(cherry picked from commit 653477c3e9)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:53:59 +08:00
Zhi Wei Jian 349b4cf8a9 fix(ble/bluedroid): fix GATT client cache and service discovery
(cherry picked from commit b3ff15ed31)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:53:59 +08:00
Zhi Wei Jian 638e633e04 fix(ble/bluedroid): fix GAP BLE API parameter validation
(cherry picked from commit e3311c81c4)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:53:59 +08:00
Zhi Wei Jian b464721a8d fix(ble/bluedroid): fix BLE bonding key storage validation
(cherry picked from commit 62cdd4ac38)

Co-authored-by: zhiweijian <zhiweijian@espressif.com>
2026-06-10 19:53:58 +08:00
gaoxu d51f64d719 fix(adc): fix ADC monitor channel 8/9 error
(Closes https://github.com/espressif/esp-idf/issues/17768)
2026-06-10 15:10:18 +08:00
Laukik Hase 6af1af7d99 fix(esp_tee): Harden the TEE secure services against REE manipulation
- `bootloader_flash_execute_command_common`: whitelist the flash command
   opcodes the REE actually uses; reject the rest
- `spi_flash_hal_* services`: a forged `host->driver` could hijack TEE
   control flow since the HAL dispatches through it, so swap
   `host->driver` to a TEE-rodata vtable around each HAL call
- Deny partition table and bootloader writes by default and permit
  bootloader writes only when explicitly enabled via
  `CONFIG_SPI_FLASH_DANGEROUS_WRITE_ALLOWED` option
- Protect the TEE-assigned interrupt pin configuration against REE
- Validate nested DS context pointers in start/finish_sign and bound
  the result copy to the SoC max signature size
- Fix the stack usage in service dispatcher argument parsing
2026-06-10 12:06:26 +05:30
Song Ruo Jing a242565623 fix(spi_flash): gpspi flash clock could reach higher frequency 2026-06-09 21:56:36 +08:00
harshal.patil b420f20040 test(esp_hal_security): warm up ECC const-time loop before measuring 2026-06-09 15:07:55 +05:30
harshal.patil 6b8f830991 fix(esp_tee): Reset crypto peripherals before the panic-induced reset 2026-06-09 15:07:55 +05:30
harshal.patil c1f70a4cb5 fix(esp_rom): Patch ets_ecdsa_verify() to include signature bounds check 2026-06-09 15:07:53 +05:30
harshal.patil 3195c942da fix(mbedtls): validate ECDSA signature range and harden ECC memory power-down 2026-06-09 15:02:59 +05:30
hebinglin f088b73ea8 fix(ulp): fix lp uart keep wakeup triggered 2026-06-08 19:49:42 +08:00
Frantisek Hrbata 003e049ba8 fix(esp_hw_support): guard SPIRAM-dependent code with !BOOTLOADER_BUILD
The bootloader subproject's full Kconfig discovery resolves CONFIG_SPIRAM=y
when the parent app has it enabled, even though esp_psram is not linked
into the bootloader (the CMake gate is
'if(NOT non_os_build) if(CONFIG_SPIRAM) idf_component_optional_requires(PRIVATE esp_psram)').
Shared sources in esp_hw_support that #include esp_psram private headers
or call esp_psram functions guarded only by '#if CONFIG_SPIRAM' then fail
to compile in the bootloader with
"fatal error: esp_private/esp_psram_extram.h: No such file or directory".

Mirror the CMake gate in source guards: every '#if CONFIG_SPIRAM' block in
a bootloader-compiled source that touches esp_psram becomes
'#if !BOOTLOADER_BUILD && CONFIG_SPIRAM'. The leaked CONFIG_SPIRAM value
in the bootloader's sdkconfig.h is then harmless because every dependent
block evaluates to false.

Sites updated:
- esp_memory_utils.c: include of esp_psram_extram.h and all
  esp_psram_check_ptr_addr() call sites
- port/esp32{c5,c61,p4}/cpu_region_protect.c: include of
  esp_psram_extram.h (inner SPIRAM_FETCH/RODATA/PRE_CONFIGURE blocks are
  already inside outer !BOOTLOADER_BUILD guards)

Signed-off-by: Frantisek Hrbata <frantisek.hrbata@espressif.com>
2026-06-08 18:34:50 +08:00
Chen Jichang 4c86e76b8e fix(parlio): fix max valid delay value 2026-06-08 17:46:47 +08:00
Alexey Lapshin 828de81ad7 fix(libc): nano: add -lnosys to linking to avoid CMake configuration issues 2026-06-08 12:08:34 +07:00
Andrii AnoshynandClaude Opus 4.7 980de66b85 fix(protocomm): prevent out-of-bounds write in console line buffer
The console transport read loop passed &linebuf[i] to uart_read_bytes()
before checking i < LINE_BUF_SIZE, so a line of LINE_BUF_SIZE or more
bytes without a terminator wrote one byte past the 256-byte linebuf
stack array.

Gate the read on the bounds check and reserve the final byte for the NUL
terminator (LINE_BUF_SIZE - 1), so the buffer handed to esp_console_run()
stays terminated even when an overlong line is truncated.

Closes https://github.com/espressif/esp-idf/issues/18638

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-06-05 17:33:28 +08:00
luoxu 4a4b74fd6d fix(ble_mesh): Miscellaneous bugfixes according to our internal bug report (v2) 2026-06-05 14:32:21 +08:00
yangfeng 023639b75b fix: Fix missing handling for HCI_ERR_CONNECTION_EXISTS
- Closes https://github.com/espressif/esp-idf/issues/18562
2026-06-05 14:17:47 +08:00
Alexey Lapshin 79cb80979f fix(esp_tee): fix buffer overflow 2026-06-05 12:25:29 +07:00
Jiang Jiang Jian a0688c6e32 Merge branch 'bugfix/add_monitor_en_rst_in_pvt_func_backport_v6.0' into 'release/v6.0'
feat(pvt): fix monitor en rst error in pvt func on v6.0

See merge request espressif/esp-idf!49029
2026-06-05 02:55:23 +08:00
Jiang Jiang Jian 6d84812088 Merge branch 'fix/phy_cal_v6.0' into 'release/v6.0'
fix(phy): fix wifi tx failed when sta wake from deepsleep v6.0

See merge request espressif/esp-idf!49287
2026-06-05 01:18:39 +08:00
Jiang Jiang Jian 7b2945f989 Merge branch 'fix/fix_conn_recycle_assertion_at_halt_v6.0' into 'release/v6.0'
fix(ble): fix conn recycle assertion at halt on ESP32-C2 (6.0)

See merge request espressif/esp-idf!49238
2026-06-04 22:56:41 +08:00
sibeibei 9dc707c44b fix(phy): fix wifi tx failed when sta wake from deepsleep 2026-06-04 21:06:17 +08:00
yanzihan@espressif.com c348f39ad4 feat(pvt): fix monitor en rst error in pvt func on v6.0 2026-06-04 17:36:20 +08:00
C.S.M f2df45bced fix(jpeg_decoder): Add some strict check to avoid bad picture attack 2026-06-04 11:40:41 +08:00