Commit Graph
34176 Commits
Author SHA1 Message Date
Shu Chen d12614a666 Merge branch 'fix/fix_openthread_netif_glue_deinit_issue_v5.5' into 'release/v5.5'
fix(openthread): fix stack deinit by reversing netif glue teardown and hardening workflow cleanup (v5.5)

See merge request espressif/esp-idf!52399
2026-09-04 03:48:11 +00:00
Shu Chen 91159942b5 Merge branch 'feat/support_multipan_feature_host_20260813_v5.5' into 'release/v5.5'
feat(openthread): add support for the multipan feature on host devices (v5.5)

See merge request espressif/esp-idf!52377
2026-09-04 02:05:53 +00:00
Wang Meng Yang b58bae632b Merge branch 'bugfix/avrcp_version_compatibility_v5.5' into 'release/v5.5'
fix(bt): Fix the issue of AVRCP version compatibility (v5.5)

See merge request espressif/esp-idf!52088
2026-09-04 09:24:32 +08:00
Wang Meng Yang 79745d864d Merge branch 'bugfix/qos_div_zero_v5.5' into 'release/v5.5'
fix(bt): update ESP32 libbtdm_app.a to fix several issues (v5.5)

See merge request espressif/esp-idf!52054
2026-09-04 08:50:50 +08:00
Xu Si Yu ab71404e03 fix(openthread): fix stack deinit by reversing netif glue teardown and hardening workflow cleanup 2026-09-03 20:04:03 +08:00
Xu Si Yu 28561a3221 feat(openthread): support multipan feature for host device 2026-09-03 17:48:38 +08:00
Marius Vikhammer be8aead3d6 Merge branch 'fix/lightsleep_stress_task_leak_v5.5' into 'release/v5.5'
fix(esp_system): wait for idle after light sleep stress tasks (v5.5)

See merge request espressif/esp-idf!52271
2026-09-03 13:18:09 +08:00
Mahavir Jain 3dc1e9cd88 Merge branch 'fix/hmac-ds-reset-corrupts-concurrent-mpi_v5.5' into 'release/v5.5'
fix(esp_security): don't reset DS peripheral in esp_hmac_calculate (v5.5)

See merge request espressif/esp-idf!52204
2026-09-03 09:58:22 +05:30
Jin Cheng b71c37083a fix(bt): update ESP32 libbtdm_app.a to fix several issues
- fixed IntegerDividedByZero during Qos negotiation.
  Closes https://github.com/espressif/esp-idf/issues/18951
- ignored the check for bandwidth and retransmission effort when Host
  accepts the SCO connection request.
2026-09-03 11:27:05 +08:00
Mahavir Jain ffac0bf942 Merge branch 'fix/esp_image_format_v5.5' into 'release/v5.5'
fix(esp_image_format): Fix some memory-safety issues (v5.5)

See merge request espressif/esp-idf!50181
2026-09-02 14:56:09 +05:30
Mahavir Jain 051e7d6a90 Merge branch 'fix/crt_bundle_cert_header_oob_v5.5' into 'release/v5.5'
Validate cert header extent before reading it in bundle check (v5.5)

See merge request espressif/esp-idf!52185
2026-09-02 11:52:45 +05:30
Wang Meng Yang 144e211509 Merge branch 'fix/bt_memory_v5.5' into 'release/v5.5'
fix(bt_memory): Reduce memory usage in transfer (v5.5)

See merge request espressif/esp-idf!52277
2026-09-02 14:12:07 +08:00
morris ed20c20246 Merge branch 'ci/fix_the_parlio_rx_spi_test_case_v5.5' into 'release/v5.5'
ci(parlio_rx): fixed the parlio rx spi test case (v5.5)

See merge request espressif/esp-idf!52162
2026-09-02 10:49:48 +08:00
hejiaxin 3d56f31133 fix(bt_avrcp): size some AVRC command buffers 2026-09-01 11:24:02 +08:00
hejiaxin 49c18b3aaf fix(bt_l2cap): size L2CAP ERTM S-frame & RX SDU buffer 2026-09-01 11:24:02 +08:00
hejiaxin 5e8f5c85fb fix(bt_sdp): size SDP TX buffers 2026-09-01 11:24:02 +08:00
hejiaxin 6bfe3c70e3 fix(bt_rfcomm): size RFCOMM TX buffers by peer MTU 2026-09-01 11:23:59 +08:00
hejiaxin 3e9012b5e3 fix(bt_hid): size HID TX buffers to report length 2026-09-01 11:21:41 +08:00
Marius Vikhammer 85bb3faa5f fix(esp_system): delay after light sleep stress cleanup 2026-09-01 10:39:56 +08:00
Marius Vikhammer 283d7b5ebd fix(esp_system): wait for idle after light sleep stress tasks
Self-deleted worker tasks are only freed once idle runs. A 500us
periodic esp_timer can starve that cleanup and trip Unity's leak check.
2026-09-01 10:30:42 +08:00
Shreyas Sheth eb0df1622d fix(esp_wifi): Harden dpp Auth confirm and drop mismatched auth confirms 2026-08-31 14:04:19 +05:30
harshal.patil 347727b122 fix(mbedtls): validate cert header extent before reading it in bundle check
esp_crt_check_bundle() read the 4-byte certificate header (name_len,
key_len) via esp_crt_get_len() after only checking that the cert's
start offset lies inside the bundle, so a crafted bundle whose first
or last certificate starts within the final 3 bytes caused a transient
out-of-bounds read of up to 3 bytes before the extent check rejected
it. Require the whole header to lie inside the bundle before reading
it.
2026-08-31 10:25:48 +05:30
morris 210ac40082 Merge branch 'fix/jpeg_enc_header_oob_v5.5' into 'release/v5.5'
fix(jpeg): validate encoder buffer sizes before header/DMA access (backport v5.5)

See merge request espressif/esp-idf!52123
2026-08-31 11:11:01 +08:00
Ashish Sharma 28268f348c fix(esp_security): don't reset DS peripheral in esp_hmac_calculate
esp_hmac_calculate() enabled and reset the Digital Signature (DS)
peripheral, but HMAC has no dependency on DS (the dependency runs the
other way: a DS operation uses HMAC/SHA).

The DS peripheral drives the RSA (MPI) accelerator internally, so pulsing
the DS reset also resets the RSA datapath. This coupling exists on every
target that has the DS peripheral: the MPI reset routine itself clears the
DS reset "otherwise RSA is held in reset".

esp_hmac_calculate() holds only the HMAC and SHA/AES locks, not the MPI
lock, so it can corrupt a concurrent RSA/MPI operation. On multi-core
targets (e.g. ESP32-P4, ESP32-S31, ESP32-S3) an HMAC on one core resets an
RSA op running on another core; on single-core targets (e.g. ESP32-C5) the
same corruption happens when an HMAC preempts an in-flight RSA op. The
result is a wrong RSA result or a crash in the computation.

Remove the DS peripheral enable/reset from the HMAC path. SHA, which HMAC
depends on, is enabled independently, so the HMAC output is unchanged.
This also drops a few redundant register writes.
2026-08-31 10:56:56 +08:00
Konstantin Kondrashov b116ab3a21 fix(bootloader): increase partition table offset for ESP32-P4 in affected test configs 2026-08-28 17:15:49 +03:00
Konstantin Kondrashov 777c72a01e fix(esp_image_format): validate MMU page size 2026-08-28 17:15:49 +03:00
Konstantin Kondrashov 85d56ea446 fix(esp_image_format): verify length of segment #0 for app description 2026-08-28 17:15:49 +03:00
Konstantin Kondrashov 95c4491fba fix(esp_image_format): Verify image segment count 2026-08-28 17:15:49 +03:00
Mahavir Jain fd0b33dfda Merge branch 'bugfix/memory-safety-and-validation_v5.5' into 'release/v5.5'
fix(security): findings from project Vanessa (v5.5)

See merge request espressif/esp-idf!50411
2026-08-28 17:17:10 +05:30
Jiang Jiang Jian d90d34f89a Merge branch 'bugfix/nan_vulnerabilities_v5.5' into 'release/v5.5'
fix(nan): Fix bug bounty reported and discovered vulnerabilities in NAN Rx (Backport v5.5)

See merge request espressif/esp-idf!51300
2026-08-28 18:00:40 +08:00
morris 9c01eb00e3 Merge branch 'fix/isp_error_when_rgb888_input_v5.5' into 'release/v5.5'
fix(isp): initialize Color defaults for RGB DMA output (v5.5)

See merge request espressif/esp-idf!51648
2026-08-28 17:38:52 +08:00
Marius Vikhammer af64bbd9e2 Merge branch 'bugfix/heap_task_tracking_isr_safe_v5.5' into 'release/v5.5'
fix(heap): use critical section for task tracking locks (v5.5)

See merge request espressif/esp-idf!52010
2026-08-28 15:56:38 +08:00
Chen Jichang 1673d8b56d ci(parlio_rx): fixed the parlio rx spi test case 2026-08-28 14:36:35 +08:00
Wang Meng Yang b5b7c57da3 Merge branch 'fix/aireview_obex_v5.5' into 'release/v5.5'
fix(bt_obex): fix some bugs in bluedroid obex (v5.5)

See merge request espressif/esp-idf!52006
2026-08-28 08:42:46 +08:00
Mahavir Jain c13bec45b1 Merge branch 'fix/esp32s2_aes_dma_psram_partial_block_hang_v5.5' into 'release/v5.5'
Avoid ESP32-S2 Crypto DMA stall on PSRAM output with partial blocks (v5.5)

See merge request espressif/esp-idf!51876
2026-08-27 12:05:36 +05:30
C.S.M ceb7443c4d fix(jpeg): validate encoder buffer sizes before header/DMA access
Bound JPEG header emission by outbuf capacity and reject undersized
input buffers before programming TX DMA to avoid heap corruption and
out-of-bounds DMA reads.

(cherry picked from commit a7ac00b812)
2026-08-27 13:51:22 +08:00
Marius Vikhammer d16bdf622b Merge branch 'bugfix/c5_mac_ext_byte_order_v5.5' into 'release/v5.5'
fix(efuse): correct MAC_EXT byte order on ESP32-C5 and ESP32-H21 (v5.5)

See merge request espressif/esp-idf!52033
2026-08-27 11:08:16 +08:00
Island 19839f076d Merge branch 'change/ble_update_lib_20260824_v5.5' into 'release/v5.5'
change(ble): [AUTO_MR] 20260824 - Update ESP BLE Controller Lib (5.5)

See merge request espressif/esp-idf!52019
2026-08-26 22:00:50 +08:00
yangfeng d4d86a90f2 fix(bt): Fix the issue of AVRCP version compatibility 2026-08-26 15:55:53 +08:00
Rahul Tank 01cc6a6580 Merge branch 'bugfix/fix_pawr_conn_issues_v5.5' into 'release/v5.5'
fix(nimble): bound PAwR synced connect retries in the example (v5.5)

See merge request espressif/esp-idf!52026
2026-08-25 16:08:24 +05:30
Akshat Agrawal 77b57d35cf fix(nan): Fix bug bounty reported and discovered vulnerabilities in NAN Rx 2026-08-25 14:31:49 +05:30
Meet Patel 60b843b7ea fix(efuse): correct MAC_EXT byte order on ESP32-C5 and ESP32-H21
A single 16-bit MAC_EXT field was read little-endian, reversing FF:FE
used for IEEE 802.15.4 EUI 64 extension.

Closes https://github.com/espressif/esp-idf/issues/18955
2026-08-25 13:51:32 +05:30
Jiang Jiang Jian d72f03f0ca Merge branch 'bugfix/a2dp_sink_nego_sbc_v5.5' into 'release/v5.5'
fix(bt): do not cap AVDTP Discover results by local SEP count (v5.5)

See merge request espressif/esp-idf!51752
2026-08-25 16:11:26 +08:00
Zhao Wei Liang 173daa4bbc change(ble): [AUTO_MR] Update lib_esp32c6 to cdaefea1
(cherry picked from commit d2210c2c26)

Co-authored-by: zhaoweiliang <zhaoweiliang@espressif.com>
2026-08-25 14:05:19 +08:00
Zhao Wei Liang ba5f877e69 change(ble): [AUTO_MR] Update lib_esp32c5 to cdaefea1
(cherry picked from commit 85d8971199)

Co-authored-by: zhaoweiliang <zhaoweiliang@espressif.com>
2026-08-25 14:05:18 +08:00
Zhao Wei Liang 110239b3a3 change(ble): [AUTO_MR] Update lib_esp32h2 to cdaefea1
(cherry picked from commit b3ba8cad9a)

Co-authored-by: zhaoweiliang <zhaoweiliang@espressif.com>
2026-08-25 14:05:17 +08:00
Ashish Sharma 2312716f8c fix(esp_http_client): return an error when append_string realloc fails 2026-08-25 14:00:19 +08:00
Ashish Sharma 25f5e205cd fix(mbedtls): bound *iv_off in DMA esp_aes_crypt_ofb to prevent OOB read 2026-08-25 13:35:50 +08:00
Ashish Sharma 4751d66bd0 fix(esp_tee): guard calloc overflow and attestation leak 2026-08-25 13:35:50 +08:00
Ashish Sharma 7ca54ff43a fix(mbedtls): validate crypto input lengths (TEE OOB, auth-bypass, overflows) 2026-08-25 13:35:50 +08:00