Commit Graph
39280 Commits
Author SHA1 Message Date
Jiang Jiang Jian b6df7cff06 Merge branch 'fix/154_mac_receive_at_v5.2' into 'release/v5.2'
fix(ieee802154): skip receive_at when rx window already expired (v5.2)

See merge request espressif/esp-idf!51366
2026-08-06 11:22:22 +08:00
Jiang Jiang Jian 541237330e Merge branch 'test/idf-additions-coverage_v5.2' into 'release/v5.2'
test(freertos): expand IDF additions test coverage (v5.2)

See merge request espressif/esp-idf!50824
2026-08-06 11:21:46 +08:00
Jiang Jiang Jian 5911e48eba Merge branch 'fix/fatfs_6682_fat32_overflow_v5.2' into 'release/v5.2'
fix(storage/fatfs): fix FAT32 mount integer overflow (CVE-2026-6682) [v5.2 backport]

See merge request espressif/esp-idf!50449
2026-08-06 11:21:23 +08:00
Jiang Jiang Jian 02406f2553 Merge branch 'fix/s3_xip_opt_os_startup_v5.2' into 'release/v5.2'
fix(mspi): fixed possible boot failure in some builds when psram is enabled (v5.2)

See merge request espressif/esp-idf!48592
2026-08-06 11:16:36 +08:00
Euripedes Rocha 863af334c9 Merge branch 'fix/esp_netif-oom-null-checks-v5.5_v5.2' into 'release/v5.2'
fix(esp_netif): harden NULL and OOM handling in netif APIs (SEC-1189, SEC-1190) (v5.2)

See merge request espressif/esp-idf!50786
2026-08-05 10:29:06 +02:00
Island 2d3581bcb1 Merge branch 'fix/ble_mesh_added_gatt_err_rsp_v5.2' into 'release/v5.2'
fix(ble_mesh): align GATTS read/write response handling with ATT (5.2)

See merge request espressif/esp-idf!51459
2026-08-05 16:03:03 +08:00
zwx 9edde96655 fix(ieee802154): skip receive_at when rx window already expired 2026-08-05 06:59:35 +00:00
Wang Meng Yang 5ce46f2764 Merge branch 'change/refactor_hidh_datapath_v5.2' into 'release/v5.2'
Change/refactor hidh datapath[backport v5.2]

See merge request espressif/esp-idf!51283
2026-08-05 14:23:43 +08:00
Jiang Jiang Jian c791648329 Merge branch 'bugfix/nan_vulnerabilities_v5.2' into 'release/v5.2'
fix(nan): Fix bug bounty reported and discovered vulnerabilities in NAN Rx (Backport v5.2)

See merge request espressif/esp-idf!51403
2026-08-05 11:52:24 +08:00
Jiang Jiang Jian b88f87a771 Merge branch 'fix/rtc_retain_mem_sb_fast_wakeup_ptr_v5.2' into 'release/v5.2'
fix(bootloader_support): fix RTC retain mem offset for secure boot fast wakeup (v5.2)

See merge request espressif/esp-idf!51271
2026-08-05 10:44:04 +08:00
Island f030f5f862 Merge branch 'fix/ble_log_compression_add_local_header_file_v5.2' into 'release/v5.2'
feat(ble_log): mirror local compression headers (5.2)

See merge request espressif/esp-idf!50948
2026-08-04 19:48:20 +08:00
Euripedes Rocha FilhoandCursor 09550486eb fix(esp_netif): harden NULL and OOM handling in netif APIs
Use a temporary pointer for br_glue port-list realloc so a failure does
not clobber the existing array. Reject NULL mac in esp_netif_set_mac and
validate config->base in esp_netif_new_api before use.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-04 08:57:02 +02:00
Wang Meng Yang 1377dac554 Merge branch 'fix/aireview_critical_v5.2' into 'release/v5.2'
fix: Fix some critical bugs in classic bt (v5.2)

See merge request espressif/esp-idf!51293
2026-08-04 14:15:22 +08:00
Luo Xu 3d204ee3d5 feat(ble_log): mirror local compression headers
(cherry picked from commit ee732a4591)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-08-04 11:58:57 +08:00
Luo Xu ea5e0f245d fix(ble_mesh): align GATTS read/write response handling with ATT
bt_mesh_bta_gatts_cb did not always answer ATT Read/Write Requests:
- READ: on a callback error it only logged a warning and sent nothing; a
  0-byte read (Read Blob at an offset equal to the value length) also sent
  nothing, although it is a successful empty read.
- WRITE: on a callback error it sent nothing, and a partial/zero write was
  treated as success.
- Both: when the handle was not found or the attribute had no read/write
  callback, the request was silently dropped.

An ATT Request must always be answered:

- READ: len >= 0 is success -> Read Response (a 0-byte read yields an empty
  value); len < 0 -> ATT Error Response carrying the callback's error code
  (-len, since BLE_MESH_GATT_ERR(x) == -x). The copy length is clamped to
  the source buffer size as a defensive bound. If the handle is unknown or
  the attribute has no read callback, respond with INVALID_HANDLE /
  READ_NOT_PERMITTED.
- WRITE: when need_rsp is set, always reply. len == write length -> Write
  Response; otherwise (negative ATT error, partial write, or 0) -> ATT
  Error Response (the negative code, or UNLIKELY for partial/0). If the
  handle is unknown or the attribute has no write callback, respond with
  INVALID_HANDLE / WRITE_NOT_PERMITTED. Write Without Response still sends
  no response.

A non-success status passed to BTA_GATTS_SendRsp is turned into an ATT
Error Response by the GATT layer (gatt_sr_process_app_rsp ->
gatt_send_error_rsp).


(cherry picked from commit ed1f4de3a3)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-08-03 21:43:32 +08:00
Island 4a270847e9 Merge branch 'feat/update_mesh_lib_to_supported_get_lib_ver_v5.2' into 'release/v5.2'
Feat/update mesh lib to supported get lib ver (5.2)

See merge request espressif/esp-idf!51169
2026-08-03 11:30:56 +08:00
Xiao Xufeng ecab1fec19 fix(mspi): fixed possible boot failure in some builds when psram is enabled
A typical scenario is: when XIP on PSRAM enabled, compiler optimization level is Os. Under certain binary layout, boot hangs and backtrace points to `esp_sleep_config_gpio_isolate`.

The root cause is that, during PSRAM initialization, it calls esp_gpio_reserve, which happens to place before the reported function. However, after call, there is no barrier before the clock adjustment in `mspi_timing_enter_low_speed_mode`. The clock gets changed when the cache is still fetching data, resulting in the corrupted data in the end of the cache line.

This commits add spi_flash_disable_cache as a barrier to make sure the cache transactions is finished before the clock switch.
2026-08-02 03:35:44 +08:00
Akshat Agrawal 0ea62f0b58 fix(nan): Fix bug bounty reported and discovered vulnerabilities in NAN Rx 2026-07-31 12:46:46 +05:30
harshal.patil e37d6e40b0 refactor(esp_system): deduplicate ROM fast wake RTC digest reservation
The digest length and the condition that reserves it at the end of RTC RAM were
duplicated in seven places. Hold the reservation in a hidden Kconfig value that
is zero when the feature does not apply, so every consumer subtracts it
unconditionally, and derive ESP_SECURE_BOOT_DIGEST_LEN from it.
2026-07-31 11:28:31 +08:00
Jiang Jiang Jian 00c8f05ebf Merge branch 'bugfix/fix_espnow_data_rate_error_v5.2' into 'release/v5.2'
fix(wifi): fixed espnow data rate overridden by stale rate control (v5.2)

See merge request espressif/esp-idf!51306
2026-07-31 10:35:41 +08:00
morris 63ad3cc73a Merge branch 'fix/fix_i2s_i80_color_size_check_v5.2' into 'release/v5.2'
fix(lcd): add color size check for i80 and boundary check for rgb (v5.2)

See merge request espressif/esp-idf!50980
2026-07-31 10:18:45 +08:00
Rahul Tank 940c834103 Merge branch 'bugfix/fix_pawr_conn_event_v5.2' into 'release/v5.2'
fix(nimble):  Deliver PAwR peripheral CONNECT via sync callback (v5.2)

See merge request espressif/esp-idf!51257
2026-07-30 20:45:50 +05:30
hejiaxin 556e7cdad5 fix(bt_stack): Fix some critical bugs in classic_bt stack
related: obex, smp, pbap, sdp, rfcomm, stack_dm

- Deinit function doesn't delete connection when OBEX_DYNAMIC_MEMORY is on
- Union tGOEPC_DATA sometimes is free by osi_free in some cases when it contains mtu_id
- Add correct free and return solution after fail
- Fix symbol mistake in mod calculation
- Fix pointer-related UAF problems and memory free problems
- Fix buffer overflows and out-of-bounds access
- Fix infinite loops triggered by integer overflow wraparound
- Fix double free
- Change layer_specific usage to avoid heap overflow
- Add some NULL check for pointers
- Fix sdp_db free function
- Fix state table mismatch
2026-07-30 17:30:53 +08:00
Wang Meng Yang 32c20d92e2 Merge branch 'fix/bluedroid_aireview_v5.2' into 'release/v5.2'
Fix/bluedroid aireview (v5.2)

See merge request espressif/esp-idf!51298
2026-07-30 14:29:38 +08:00
zhangyanjiao 3ea731c2eb fix(wifi): fixed espnow data rate overridden by stale rate control 2026-07-30 11:44:35 +08:00
Jin Cheng 18a99d2eb7 fix(bt/bluedroid): fixed incorrect eSCO packet type validation under secure connection mode in BlueDroid 2026-07-29 17:30:41 +08:00
hejiaxin 5434deb81d fix(bt): Fix some bug in stm_sco.c
- Memory safety
- State machine & logic integrity
- Resource leaks
- Edge cases check
2026-07-29 17:30:41 +08:00
morris e20d609591 Merge branch 'feat/sec_esp_drivers_v5.2' into 'release/v5.2'
fix(drivers): harden multiple peripheral drivers against local DoS and memory corruption (v5.2)

See merge request espressif/esp-idf!50562
2026-07-29 16:59:14 +08:00
Jiang Jiang Jian 6c0e248b60 Merge branch 'bugfix/supplicant_crypto_code_correction_v5.2' into 'release/v5.2'
fix(wpa_supplicant): Correct some functions in crypto porting layer (v5.2)

See merge request espressif/esp-idf!50884
2026-07-29 15:29:55 +08:00
Euripedes Rocha 83b470a85c Merge branch 'fix/lwip_sec_high_v5.2' into 'release/v5.2'
fix(lwip): high severity lwip fixes (v5.2)

See merge request espressif/esp-idf!50597
2026-07-29 06:38:36 +02:00
morris 9d97e439c8 fix(sdspi): reject oversized pre-read data before block receive
Guard start_command_read_blocks against cards that place TOKEN_BLOCK_START so early that extra_data_size exceeds the bytes expected on the current iteration. Without this check, the unsigned subtraction for will_receive underflows and propagates into memset, SPI transaction length, and memcpy counts against the fixed 516-byte block buffer.
2026-07-29 11:48:31 +08:00
morris 0b2cf7f2ea fix(i2c): release platform mutex on intr/pm_lock delete failure
ESP_RETURN_ON_ERROR inside the s_i2c_platform.mutex critical section
returns without releasing the mutex, permanently blocking all I2C
bus operations. Replace with ESP_GOTO_ON_ERROR that jumps to a
cleanup label releasing the mutex before return.
2026-07-29 11:48:31 +08:00
morris 464199f75a fix(adc): add missing input validation for channel and ret_handle
- adc_cali_curve_fitting: validate config->chan in check_valid() to
  prevent OOB access into s_adc_cali_chan_compens compensation table
- adc_filter: make s_adc_filter_free idempotent on !UNIT_BINDED SoCs
  to prevent double-free on repeated adc_del_continuous_iir_filter
- adc_cali_line_fitting(esp32): fix config && config typo to
  config && ret_handle, preventing NULL-pointer dereference
2026-07-29 11:48:31 +08:00
liqigan 521786cac2 fix(bt/bluedroid): Fixed use after free issue on osi_event_delete 2026-07-29 11:27:27 +08:00
liqigan f81ab9974a fix(bt/bluedroid): Fixed HID host reconnection bug and enabled load HID devices
Closes https://github.com/espressif/esp-idf/issues/18335
2026-07-29 11:22:58 +08:00
liqigan 214e280b67 change(bt/bluedroid): Refactored HCI ACL datapath 2026-07-29 11:12:54 +08:00
liqigan cfbb43a4fc change(bt/bluedroid): Refactored HID host datapath 2026-07-29 11:12:45 +08:00
Jiang Jiang Jian 5debc17fba Merge branch 'bugfix/fix_some_coex_bugs_260727_v5.2' into 'release/v5.2'
fix(coex): fix some coex bugs 20260727 v5.2(Backport v5.2)

See merge request espressif/esp-idf!51208
2026-07-29 10:48:59 +08:00
Jiang Jiang Jian 3653ba9bec Merge branch 'fix/fix_iram_sleep_process_access_cache' into 'release/v5.2'
fix(esp_hw_support): fix get_act_hp/lp_dbias accessed ext mem (v5.2)

See merge request espressif/esp-idf!51209
2026-07-29 10:12:06 +08:00
wuzhenghui d4d00e6ab7 fix(bootloader_support): fix RTC retain mem offset for secure boot fast wakeup
Pointer arithmetic on rtc_retain_mem_t* subtracted ESP_SECURE_BOOT_DIGEST_LEN
in struct units instead of bytes. Cast through uintptr_t so retain mem stays
below the ROM verified-image digest region on deep-sleep wake.

Partial backport of !51265 (bootloader_common_loader.c only).
2026-07-28 21:50:56 +08:00
Wang Meng Yang 1db291682a Merge branch 'bugfix/bredr_critical_bugs_v5.2' into 'release/v5.2'
fix(bt/bluedroid): fixed issues from AI review in GAP, SPP, HID, L2CAP and HCI (v5.2)

See merge request espressif/esp-idf!51082
2026-07-28 19:43:38 +08:00
David Cermak ecdf6ad91c fix(lwip): Adds nullchecks after DHCP server alloc'd pools 2026-07-28 13:19:35 +02:00
David Cermak 0895397b2f fix(lwip): reject invalid DHCP MTU option values
Validate MTU from DHCP option 26 against RFC 2132 minimum (68 bytes)
before applying to netif->mtu, preventing rogue DHCP servers from
setting MTU to 0 or other dangerously low values that cause integer
wraparound in IPv4 fragmentation.
2026-07-28 13:19:35 +02:00
Rahul Tank 5aa51e4b9c fix(nimble): Deliver PAwR peripheral CONNECT via sync callback 2026-07-28 12:59:42 +05:30
luoxu c9e5af2508 feat(ble_mesh): update lib to 79e3fee04e 2026-07-28 12:16:47 +08:00
Li Shuai 61979fda9a change(esp_hw_support): optimize get hp/lp dbias implementation iram or flash usage 2026-07-27 19:13:28 +08:00
muhaidong 3bbb0c24a8 fix(coex): fix some coex bugs 20260727 v5.2
1. feat(coex): add 802.15.4 status for coex
2. fix(coex): fix ieee802.15.4 external coex tx/rx stage handling
3. fix(coex): move 15.4 register configuration to 15.4 init
4. fix(coex): fix coex status get issue
2026-07-27 16:37:22 +08:00
Xu Si Yu c7ad5f20ce fix(coex): move 15.4 register configuration to 15.4 init 2026-07-27 16:27:37 +08:00
Xu Si Yu cdd8c1e261 feat(coex): add 802.15.4 status for coex 2026-07-27 16:22:57 +08:00
Luo Xu 641ec20d67 feat(ble_mesh): supported get lib version
(cherry picked from commit 56f78da32c)

Co-authored-by: luoxu <luoxu@espressif.com>
2026-07-27 10:03:10 +08:00