Commit Graph
37404 Commits
Author SHA1 Message Date
Ashish Sharma c4de8d52e7 fix(ws): enforce payload length encoding minimality and MSB constraints
Independently reported in parallel by DatanoiseTV <syso.berlin@icloud.com>
2026-07-07 17:46:23 +08:00
Ashish Sharma ebe89b6fb5 fix(ws): reject RSV bits, reserved opcodes, fragmented control frames 2026-07-07 17:43:16 +08:00
morris fbe6d9005a Merge branch 'refactor/move_regdma_entry_config_to_driver_layer_sdm' into 'master'
refactor(sdm): move sleep retention config into driver layer

See merge request espressif/esp-idf!50364
2026-07-07 00:07:33 +08:00
Tomas Rohlinek 5fde421955 Merge branch 'fix/fatfs_vulnerabilities' into 'master'
fix(fatfs): harden against runZero 2026 FatFs bugs

See merge request espressif/esp-idf!50362
2026-07-06 15:20:15 +02:00
Tomáš Rohlínek 5716f444d4 fix(storage/fatfs): record non-applicable runZero 2026 CVEs in SBOM
Document the three runZero "Seven FatFs bugs" CVEs that require no source change
in this component, so vulnerability scanners have their disposition:

  - CVE-2026-6684: GPT partition-scan loop DoS. Already fixed upstream in R0.16,
    where test_gpt_header() caps the partition-entry count at 128.
  - CVE-2026-6686: read of uninitialized clusters after f_lseek() past EOF.
    Longstanding, behavioral; not a memory-safety defect and zero-filling every
    extended cluster is prohibitively costly on flash.
  - CVE-2026-6688: long-filename overflow in downstream callers. Not exposed in
    ESP-IDF; vfs_fat.c uses bounded copies and fname is bounded by FF_MAX_LFN.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 13:39:24 +02:00
Tomáš Rohlínek 838ea02c56 fix(storage/fatfs): clamp exFAT volume-label length in f_getlabel() (CVE-2026-6687)
f_getlabel() extracts the exFAT volume label with a loop bounded by the on-disk
byte dj.dir[XDIR_NumLabel] (0-255):

    for (si = di = hs = 0; si < dj.dir[XDIR_NumLabel]; si++)
        wc = ld_16(dj.dir + XDIR_Label + si * 2);

The exFAT label field holds at most 11 UTF-16 units (22 bytes). A crafted
directory entry with a larger count both reads past the 22-byte label field and,
through put_utf(... &label[di], 4), writes past the end of the caller-provided
label buffer (the canonical API examples use small fixed stack buffers) -> stack
buffer overflow.

Clamp the character count to the exFAT maximum of 11 before the extraction loop.
Record the CVE in the component SBOM.

Note: f_getlabel() takes no destination-buffer size, so under UTF-8 output
(FF_LFN_UNICODE == 2) 11 units can still expand to up to 34 bytes; the clamp
downgrades this from attacker-unbounded to spec-bounded. ESP-IDF's VFS layer
does not call f_getlabel(); direct callers on untrusted media should size their
buffer accordingly. A complete fix requires an upstream size-aware API change.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 13:38:59 +02:00
Tomáš Rohlínek 98416b7e13 fix(storage/fatfs): guard dirty-cache refill against unsigned LBA wrap (CVE-2026-6685)
After a direct multi-sector disk_read()/disk_write(), FatFs decides whether the
cached sector overlaps the direct-I/O range with:

    fp->sect - sect < cc          (and the FF_FS_TINY variant fs->winsect - sect < cc)

`sect`, `fp->sect` and `fs->winsect` are unsigned LBA_t. On 32-bit LBA_t builds,
if the cached sector is below `sect`, the subtraction wraps to a huge value that
can still compare `< cc`, so the code computes a bogus large offset:

  - in f_write() it mis-copies from the direct write buffer (data corruption);
  - in f_read() it is worse: memcpy(rbuff + (wrapped_offset * SS), ...) is an
    out-of-bounds WRITE into the caller-supplied read buffer.

Add an explicit lower-bound check (fp->sect >= sect, resp. fs->winsect >= sect)
before the range test on both the read and write paths and both the FF_FS_TINY
and normal variants, so the condition is exactly "cached sector lies within
[sect, sect + cc)". Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 13:38:29 +02:00
Tomáš Rohlínek 7d73545564 fix(storage/fatfs): reject empty exFAT cluster heap and guard divisor (CVE-2026-6683)
The FAT12/16/32 mount path rejects a zero cluster count, but the exFAT path
accepted NumClusters == 0. That yields fs->n_fatent == 2, and sync_fs() later
computes the "percent in use" field as:

    ... * 100 / (fs->n_fatent - 2)

which is a division by zero (n_fatent - 2 == 0) -> crash. On a device that
syncs during an update this can brick the unit.

Reject ncl == 0 at exFAT mount time, and add a defense-in-depth
`fs->n_fatent > 2` guard around the division in sync_fs() so the divisor can
never be zero even if some future path produces such a filesystem object.
Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 13:37:59 +02:00
Tomáš Rohlínek 81ec08b949 fix(storage/fatfs): fix exFAT mount integer overflow (CVE-2026-6682)
The exFAT mount path validates that the media is large enough to hold the
declared cluster heap with:

    if (maxlba < (QWORD)fs->database + ncl * fs->csize) ...

`ncl` (DWORD, up to MAX_EXFAT) and `fs->csize` (WORD) are both promoted to
`unsigned int`, so `ncl * fs->csize` is evaluated in 32-bit arithmetic and can
wrap before the QWORD promotion of the sum. A crafted image with a large
NumClusters/SecPerClus can therefore make an undersized volume pass the "size
is large enough" check; subsequent cluster->sector math then addresses media
outside the actual device.

Promote the multiply to 64-bit ((QWORD)ncl * fs->csize). Apply the same
promotion to the bitmap-base computation ((LBA_t)fs->csize * (bcl - 2)), which
has the identical overflow shape. Record the CVE in the component SBOM.

Reference: https://www.runzero.com/blog/fatfs-bugs/
2026-07-06 13:37:28 +02:00
Tomáš Rohlínek ae0fad3bac fix(storage/fatfs): correct SBOM version to R0.16
The vendored FatFs sources are revision R0.16 (FF_DEFINED == 80386, per
components/fatfs/src/ff.h and ff.c) but the SBOM recorded R0.15. Correct the
recorded version so vulnerability tracking matches the actual sources.
2026-07-06 13:36:59 +02:00
morris 18f50fefa9 Merge branch 'feat/esp_macro_align_up_down' into 'master'
refactor(esp_common): centralize ALIGN_UP/ALIGN_DOWN into esp_macros.h

See merge request espressif/esp-idf!50335
2026-07-06 19:09:14 +08:00
Nilesh Kale 4eaa03abf5 Merge branch 'feat/enable_aes_gcm_support_for_esp32s31' into 'master'
feat: enable AES GCM support for ESP32-S31

Closes IDF-15529

See merge request espressif/esp-idf!47564
2026-07-06 17:35:39 +08:00
Martin Vychodil ee0099188c Merge branch 'fix/vfs_fatfs_test_stale_partition' into 'master'
test(vfs): reformat WL FATFS in setup to avoid stale-partition flakes

See merge request espressif/esp-idf!50393
2026-07-06 17:31:59 +08:00
Aditya Patwardhan 5ee87f7b2c Merge branch 'fix/nvs-encrypted-partition-destructor-zeroize' into 'master'
fix(nvs_flash): zeroize XTS contexts when encrypted partition is destroyed

See merge request espressif/esp-idf!47585
2026-07-06 14:29:27 +05:30
Martin VychodilandCursor 99f87d8ac9 test(vfs): reformat WL FATFS in setup to avoid stale-partition flakes
Reformat the test partition before each mount so those tests always start from
a known-empty filesystem.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-06 10:57:30 +02:00
Mahavir Jain 7eb664f61f Merge branch 'feat/update_documentation_and_cleanup_for_esp32h4' into 'master'
Feat/update documentation and cleanup for esp32h4

See merge request espressif/esp-idf!49426
2026-07-06 14:05:31 +05:30
Chen Ji Chang b09ea896b6 Merge branch 'fix/fix_async_color_convert_csc' into 'master'
fix(dma2d): fix async color convert csc check

See merge request espressif/esp-idf!50229
2026-07-06 16:10:10 +08:00
Jiang Jiang Jian 309b3e82ec Merge branch 'fix/ble_mesh_disable_adv_pkt_discard_log' into 'master'
fix(ble_mesh): Disable warning logging when advertising packets are discarded

Closes BLERP-2945

See merge request espressif/esp-idf!50146
2026-07-06 15:13:06 +08:00
morris 4704a99af3 refactor(sdm): move sleep retention config into driver layer
Move SDM regdma retention descriptors out of esp_hal_gpio and into
per-target
esp_driver_sdm sources so the driver owns its backup scope and restore
flow.
2026-07-06 15:09:37 +08:00
Jiang Jiang Jian 9126adadb9 Merge branch 'fix/ble_mesh_fixed_issues' into 'master'
Resolve NVIDIA-reported BLE mesh stack issues

Closes SEC-1116, SEC-1069, SEC-761, SEC-1068, SEC-1130, and SEC-1185

See merge request espressif/esp-idf!50176
2026-07-06 15:09:30 +08:00
Mahavir Jain 442cc028b5 Merge branch 'fix/fix_esp_http_client_cross_origin_credentials' into 'master'
fix(esp_http_client): strip Authorization header on cross-origin redirect

Closes SEC-228 and SEC-049

See merge request espressif/esp-idf!48820
2026-07-06 12:20:51 +05:30
nilesh.kale ec6921b9df feat: enable AES GCM support for ESP32-S31 2026-07-06 11:51:05 +05:30
Ashish Sharma f7b8db2f2f feat(espcoredump): migrate to esp sha256 implementation from mbedtls sha256 2026-07-06 11:11:12 +05:30
morris 651d6a283f refactor(esp_common): centralize ALIGN_UP/ALIGN_DOWN into esp_macros.h
Remove ~50 duplicate local definitions of ALIGN_UP/ALIGN_DOWN/ALIGN_UP_BY/
ALIGN_DOWN_BY across the codebase and replace them with canonical
ESP_ALIGN_UP/ESP_ALIGN_DOWN from esp_macros.h.
2026-07-06 13:36:06 +08:00
Ashish Sharma 7d9f061cc1 fix(mbedtls): fixes TLS1.3 server failing with dynamic buffer 2026-07-06 10:38:10 +05:30
Aditya Patwardhan 2468defbff Merge branch 'feat/update_documentation_and_cleanup_for_s31' into 'master'
enable tests and cleanup JIRA references for s31

Closes IDF-14629 and IDF-14628

See merge request espressif/esp-idf!49273
2026-07-06 10:31:47 +05:30
Chen Jichang 5123e1c634 fix(dma2d): fix async color convert csc check 2026-07-06 12:43:35 +08:00
nilesh.kale fe18ed97dd feat: added call to aquire clock source for H4 and H21 AES crypto 2026-07-06 10:12:35 +05:30
Marius Vikhammer 61c798000f Merge branch 'feature/enable_more_linux_examples' into 'master'
feat(linux): enable more examples for linux target

See merge request espressif/esp-idf!50172
2026-07-06 11:40:51 +08:00
Song Ruo Jing e4a269d793 Merge branch 'bugfix/dma2d_dequeue_mechanism' into 'master'
fix(dma2d): add a dequeue mechanism for dma2d driver

See merge request espressif/esp-idf!49925
2026-07-06 11:19:53 +08:00
morris 5c88f19a39 Merge branch 'bugfix/i2c_set_but_not_used_variable' into 'master'
fix(i2c): remove unused but set variables

Closes IDF-15788

See merge request espressif/esp-idf!50348
2026-07-06 11:08:56 +08:00
Jiang Jiang Jian dc6ff3a91e Merge branch 'feat/update_pmu_pau_reg_description' into 'master'
feat(soc): update esp32c61 PMU & PAU reg header descriptions

See merge request espressif/esp-idf!50240
2026-07-06 10:35:29 +08:00
Wang Meng Yang cbe15485ce Merge branch 'bugfix/fix_some_ctrl_bugs' into 'master'
fix(bt/controller): Fixed BR/EDR controller bugs found by regression tests on ESP32-S31

Closes BTQABR2023-776, BTQABR2023-786, BTQABR2023-800, BT-4378, BT-4381, and BT-4386

See merge request espressif/esp-idf!50251
2026-07-06 08:56:39 +08:00
Mahavir Jain 1e2b539c1c Merge branch 'bugfix/memory-safety-and-validation' into 'master'
fix(security): findings from project Vanessa

Closes SEC-1110, SEC-1115, SEC-1128, SEC-1144, SEC-763, SEC-1159, SEC-1058, SEC-609, SEC-1146, SEC-1163, SEC-1148, SEC-1176, SEC-1177, SEC-109, SEC-1156, SEC-1173, SEC-1174, SEC-1175, SEC-1117, SEC-1171, SEC-231, SEC-1182, SEC-1188, SEC-1157, SEC-328, and SEC-1131

See merge request espressif/esp-idf!50093
2026-07-03 23:26:21 +05:30
Erhan Kurubas 0586fb67c2 Merge branch 'coredump_test_fixes' into 'master'
Coredump fixes

Closes IDF-15881 and IDF-13849

See merge request espressif/esp-idf!48439
2026-07-03 16:38:00 +02:00
Jiang Jiang Jian c7f22a4508 Merge branch 'fix/fix_sleep_cache_writeback_logic' into 'master'
fix(esp_hw_support): fix esp32s31 sleeping cache writeback logic

Closes PM-807

See merge request espressif/esp-idf!50346
2026-07-03 22:29:21 +08:00
Tomas Rezucha a7a89f98c9 Merge branch 'docs/usb_wakeup_source' into 'master'
docs(sleep): Update light-sleep USB wake-up source

See merge request espressif/esp-idf!49990
2026-07-03 15:16:12 +02:00
Mahavir Jain 8d9fe4d5fe Merge branch 'fix/revert_redundant_rom_pmp_18769' into 'master'
revert(esp_hw_support): Re-add separate D-ROM PMP entry on C6/H2

Closes IDFGH-17871

See merge request espressif/esp-idf!50161
2026-07-03 17:53:58 +05:30
Wan Lei b454f03dc8 Merge branch 'fix/twaifd_add_ci_fd_test' into 'master'
fix(driver_twai): add fd test on ci

Closes IDF-13479

See merge request espressif/esp-idf!50195
2026-07-03 19:38:33 +08:00
wuzhenghui 18dac21544 fix(esp_hw_support): fix esp32s31 sleeping cache writeback logic 2026-07-03 19:13:05 +08:00
Rahul Tank 5d40723bdf Merge branch 'bugfix/queue_att_cmd' into 'master'
feat(nimble): Defer all ATT commands until connection event is sent to GAP layer

See merge request espressif/esp-idf!47838
2026-07-03 16:01:07 +05:30
morris d3b252d8ce fix(i2c): remove unused but set variables 2026-07-03 18:10:15 +08:00
nilesh.kale 9144db695a feat: enable tests and cleanup jira references for s31 2026-07-03 15:31:51 +05:30
Sudeep Mohanty 26b24ee2fa Merge branch 'task/buildv2_full_pipeline' into 'master'
Enable full buildv2 pipeline

Closes IDF-14180

See merge request espressif/esp-idf!49668
2026-07-03 11:28:57 +02:00
luoxu 9a3a767824 fix(ble_mesh): re-check scan dev-found cb before scan-rsp invocation 2026-07-03 17:21:14 +08:00
Ashish Sharma 7842b5170f fix(esp_tee): fix DS-lock leak, intr-matrix OOB, calloc overflow, attestation leak 2026-07-03 17:20:49 +08:00
Ashish Sharma b065c38286 fix(esp-tls): reject NULL host/url in plain-TCP and async HTTP connect 2026-07-03 17:19:05 +08:00
Ashish Sharma 7462e3c30a fix(mbedtls): validate crypto input lengths (TEE OOB, auth-bypass, overflows) 2026-07-03 17:19:05 +08:00
Ashish Sharma d64409fdb2 fix(esp_https_server): free TLS session on transport_ctx OOM in httpd_ssl_open 2026-07-03 17:19:05 +08:00
Ashish Sharma 440dd3b52a fix(esp_hal_security): clamp tag_len in aes_hal_gcm_read_tag to prevent OOB 2026-07-03 17:19:05 +08:00