Commit Graph
51571 Commits
Author SHA1 Message Date
Meet Patel eadae0b093 fix(ulp): validate bss_size before zeroing ULP BSS region
Crafted ULP binaries could specify a bss_size larger than the reserved
memory, causing memset to zero past the ULP region boundary.
2026-07-24 15:41:16 +08:00
Meet Patel 5dad0f4564 fix(pthread): avoid use-after-free when looking up TLS keys
Concurrent pthread_key_delete could free a key entry after find_key
released the lock but before callers read or invoked its destructor.
2026-07-24 15:41:16 +08:00
Jiang Jiang Jian ecd976e96b Merge branch 'fix/esp-event-security-fixes_v6.0' into 'release/v6.0'
fix(esp_event): multiple security and stability fixes (v6.0)

See merge request espressif/esp-idf!51048
2026-07-24 15:34:43 +08:00
Jiang Jiang Jian 2ea77af383 Merge branch 'fix/esp32p4_secure_boot_sig_block_v6.0' into 'release/v6.0'
fix(esp32p4): secure boot (ECDSA-P384) and flash encryption eFuse fixes (v6.0)

See merge request espressif/esp-idf!50899
2026-07-24 15:29:26 +08:00
Jiang Jiang Jian 1f6ccc0f2f Merge branch 'bugfix/vfs_fat_readdir_stat_cache_v6.0' into 'release/v6.0'
fix(fatfs): move readdir-stat cache to per-DIR stream (v6.0)

See merge request espressif/esp-idf!50904
2026-07-24 15:24:50 +08:00
morris 73fc959386 Merge branch 'docs/i2c_addr_description_v6.0' into 'release/v6.0'
docs(i2c): clarify 7-bit address usage (v6.0)

See merge request espressif/esp-idf!51090
2026-07-24 14:30:29 +08:00
morris 0ad3cc1ffb Merge branch 'doces/add_pcnt_pull_migreation_guide_v6.0' into 'release/v6.0'
docs(pcnt): add gpio pull mode migration guide (v6.0)

See merge request espressif/esp-idf!51119
2026-07-24 14:26:32 +08:00
Shu Chen 73c2fe34db Merge branch 'feat/update_phylib_on_s31_c6_for_track_v6.0' into 'release/v6.0'
feat(phy): update phy lib for esp32s31 & esp32c6 for track (v6.0)

See merge request espressif/esp-idf!50791
2026-07-24 06:04:22 +00:00
Chen Jichang dd79849654 docs(pcnt): add gpio pull mode migration guide
Closes https://github.com/espressif/esp-idf/issues/18862
2026-07-24 11:10:42 +08:00
Martin Vychodil 4a2bad6367 Merge branch 'fix/sdmmc_bdl_casting_v6.0' into 'release/v6.0'
fix(sdmmc): BDL calculate sectors cast fix + Add a better handling of devices accessing PSRAM through DMA (v6.0)

See merge request espressif/esp-idf!51044
2026-07-23 20:51:14 +08:00
Island 41687f6c0f Merge branch 'fix/ble_hidd_remove_ccc_gating_v6.0' into 'release/v6.0'
fix(esp_hid/bluedroid): remove app-layer CCC gating in HID device (6.0)

See merge request espressif/esp-idf!51007
2026-07-23 19:25:57 +08:00
Jiang Jiang Jian f44059890c Merge branch 'feature/upgrade-esp-rom-elfs_v6.0' into 'release/v6.0'
feat(tools): tools: update esp-rom-elf to version 20260528 (v6.0)

See merge request espressif/esp-idf!50847
2026-07-23 18:20:13 +08:00
Jiang Jiang Jian ca90535011 Merge branch 'bugfix/clear_ifx_tx_queue_v6.0' into 'release/v6.0'
bugfix(wifi): Clear Sta TX queue to prevent key 2 send failure (Backport v6.0)

See merge request espressif/esp-idf!50895
2026-07-23 16:05:19 +08:00
Mahavir Jain 2741444b16 Merge branch 'feat/mbedtls_update_4.1.1_v6.0' into 'release/v6.0'
Feat/mbedtls update 4.1.1 (v6.0)

See merge request espressif/esp-idf!50979
2026-07-23 13:17:21 +05:30
Island ded793522b Merge branch 'fix/ble_log_compression_add_local_header_file_v6.0' into 'release/v6.0'
feat(ble_log): mirror local compression headers (6.0)

See merge request espressif/esp-idf!50952
2026-07-23 14:23:22 +08:00
Ashish Sharma 2552d48f27 fix(mbedtls): revert to non constant time rsa key gen 2026-07-23 13:38:24 +08:00
Ashish Sharma 57ff98ca13 test(mbedtls): add PSA RSA key generation test
The test only runs with MBEDTLS_CONSTANT_TIME_PRIME_GEN disabled:
with the constant-time prime generation that is now the default,
RSA-2048 key generation takes over a minute on most targets (~86 s on
ESP32-S3), exceeding the test timeout and starving the task watchdog.
2026-07-23 13:38:24 +08:00
Ashish Sharma 73712ff5fd feat(mbedtls): add option to choose constant-time prime generation
mbedtls 4.1.1 made the small-factor test in prime generation
constant-time (a CT GCD against the product of primes up to 997, run
for every prime candidate). This makes RSA key generation roughly ten
times slower on ESP chips and starves the idle task since the software
GCD never yields, tripping the task watchdog.

Add MBEDTLS_CONSTANT_TIME_PRIME_GEN under the new "Security hardening"
menu, default y so the upstream constant-time behavior ships as the
secure default. When disabled, esp_config.h defines
MBEDTLS_MPI_PRIME_SIEVE_VARIABLE_TIME and mbedtls uses the pre-3.6.7
variable-time trial division, restoring key generation performance on
devices where no untrusted co-resident code could time key generation.
2026-07-23 13:38:24 +08:00
Ashish Sharma 8ad5504eb1 feat(mbedtls): update to version 4.1.1 2026-07-23 13:38:24 +08:00
Chen Chen 1443401e74 docs(i2c): clarify 7-bit address usage
Closes https://github.com/espressif/esp-idf/pull/18831
2026-07-23 09:13:34 +08:00
akshat e7013f62f0 bugfix(wifi): Clear Sta TX queue to prevent key 2 send failure
Also, Ensure correct return values for key 2 and key 4.
2026-07-22 18:10:00 +05:30
Wang Meng Yang 996fa1637a Merge branch 'bugfix/idf_ci_example_avrcp_v6.0' into 'release/v6.0'
fix(bt/example): Add log in the failure path for avrcp_ct_metadata example (v6.0)

See merge request espressif/esp-idf!51059
2026-07-22 17:39:59 +08:00
Jiang Jiang Jian 2f5eb98d54 Merge branch 'bugfix/fix_offchan_tx_fail_when_spiram_enabled_v6.0' into 'release/v6.0'
fix(wifi): fixed the offchan tx fail when SPIRAM_TRY_ALLOCATE_WIFI_LWIP enabled (v6.0)

See merge request espressif/esp-idf!51010
2026-07-22 16:31:26 +08:00
Jiang Jiang Jian 1396dc9aaa Merge branch 'bugfix/supplicant_crypto_code_correction_v6.0' into 'release/v6.0'
fix(wpa_supplicant): Correct some functions in crypto porting layer (v6.0)

See merge request espressif/esp-idf!50874
2026-07-22 16:26:33 +08:00
yangfeng 76a3f84779 fix(bt/example): Add log in the failure path for avrcp_ct_metadata example 2026-07-22 15:36:27 +08:00
Wang Meng Yang 3ff120c0c7 Merge branch 'bugfix/hid_host_oob_read_v6.0' into 'release/v6.0'
fix(bt/bluedroid): fixed possible 1-byte OOB read in bta_hh_ctrl_dat_act (v6.0)

See merge request espressif/esp-idf!50972
2026-07-22 14:10:05 +08:00
nilesh.kale 0a3fe51c69 fix(bootloader_support): enable XTS-AES pseudo rounds for ESP32-P4
Burn XTS_DPA_PSEUDO_LEVEL efuse on P4 (rev >= 3.0) as done for other targets.
2026-07-22 14:07:03 +08:00
nilesh.kale 783348ad44 fix(bootloader_support): set SECURE_BOOT_SHA384_EN eFuse on ESP32-P4
Set SECURE_BOOT_SHA384_EN when enabling ECDSA-P384 Secure Boot V2 on
ESP32-P4, as done on C5/H4/S31, so that ROM verifies the bootloader
using the SHA-384 scheme. The eFuse exists only on the rev >= v3.0
eFuse table, so the Kconfig option is gated on rev >= v3.0.
2026-07-22 14:07:03 +08:00
nilesh.kale a3ce319a87 fix(esp_rom): correct ESP32-P4 secure boot signature block layout 2026-07-22 14:07:03 +08:00
Island aaaadb64be Merge branch 'fix/ble-log-store-access-fault_v6.0' into 'release/v6.0'
fix: Ensure BLE Log Global Variables in Internal RAM (6.0)

See merge request espressif/esp-idf!51036
2026-07-22 14:02:37 +08:00
Mahavir Jain a96952e277 Merge branch 'fix/httpd-content-length-truncation_v6.0' into 'release/v6.0'
fix(esp_http_server): reject Content-Length above UINT32_MAX (backport v6.0)

See merge request espressif/esp-idf!50493
2026-07-22 09:22:58 +05:30
muhaidong c317ce370f fix(phy): removed all librfate logic from cmake 2026-07-22 11:17:52 +08:00
zhuanghang 78bbb23925 feat(phy): update phy lib for esp32s31 & esp32c6 for track 2026-07-22 11:17:11 +08:00
zhangyanjiao bb093bc6bc fix(wifi): fixed the offchan tx fail when SPIRAM_TRY_ALLOCATE_WIFI_LWIP enabledy 2026-07-22 11:09:36 +08:00
Jiang Jiang Jian 480c5435d8 Merge branch 'bugfix/dpp_backport_v6.0' into 'release/v6.0'
fix(esp_wifi): Backport dpp and other fixes

See merge request espressif/esp-idf!50723
2026-07-22 11:01:37 +08:00
Kapil Gupta 9fb8a3ddaa fix(wpa_supplicant): Correct some functions in crypto porting layer 2026-07-22 10:50:19 +08:00
Jiang Jiang Jian 8dec036cdd Merge branch 'feature/adds_ipc_isr_safe_api_v6.0' into 'release/v6.0'
feat(ipc_isr): Adds IPC ISR safe API to stall other CPU (v6.0)

See merge request espressif/esp-idf!50964
2026-07-22 10:44:59 +08:00
Jiang Jiang Jian ef47f0573c Merge branch 'change/ble_update_lib_20260717_v6.0' into 'release/v6.0'
change(ble): [AUTO_MR] 20260717 - Update ESP BLE Controller Lib (6.0)

See merge request espressif/esp-idf!50932
2026-07-22 10:42:32 +08:00
Jiang Jiang Jian 7bcd65c9be Merge branch 'fix/fix_esp_tee_iv_length_check_v6.0' into 'release/v6.0'
feat(esp_tee): ESP-TEE Security Audit fixes (v6.0)

See merge request espressif/esp-idf!50851
2026-07-22 10:37:48 +08:00
Jiang Jiang Jian 4c69588e41 Merge branch 'test/idf-additions-coverage_v6.0' into 'release/v6.0'
test(freertos): expand IDF additions test coverage (v6.0)

See merge request espressif/esp-idf!50820
2026-07-22 10:35:34 +08:00
Jiang Jiang Jian f9058d5328 Merge branch 'feat/enable_cross_signed_cert_suppport_default_v6.0' into 'release/v6.0'
feat(mbedtls): enable cross signed certificate verification support by default (v6.0)

See merge request espressif/esp-idf!50535
2026-07-22 10:30:53 +08:00
Jiang Jiang Jian bd994cb0f3 Merge branch 'bugfix/memory-safety-and-validation_v6.0' into 'release/v6.0'
fix(security): findings from project Vanessa (v6.0)

See merge request espressif/esp-idf!50391
2026-07-22 10:28:14 +08:00
Jiang Jiang Jian 5edd750418 Merge branch 'fix/harden_esp_security_v6.0' into 'release/v6.0'
fix(esp_security): harden crypto peripheral error handling (v6.0)

See merge request espressif/esp-idf!50325
2026-07-22 10:26:51 +08:00
Konstantin Kondrashov 58caaebbf5 fix(esp_event): free queued legacy cleanup ctx on loop delete
When a loop is deleted while an internal legacy "cleanup" event is still
queued (posted by a deferred self-unregistration from within a handler),
esp_event_loop_delete() drained the queue but only freed the post payload,
leaking the heap copy of the handler context allocated for the legacy path.

Free ctx->handler_ctx for queued legacy cleanup events while draining the
queue, mirroring the cleanup done in esp_event_loop_run().

Add a regression test that leaves a legacy cleanup event queued and asserts
no memory is leaked on loop deletion.
2026-07-21 17:15:20 +03:00
Konstantin Kondrashov 0a66277300 fix(esp_event): clear running_task before releasing mutex on tick timeout
When esp_event_loop_run() exited via the ticks-expired break path,
loop->running_task was left pointing to the current task handle.
Any subsequent trylock in esp_event_handler_unregister_with_internal()
would see a stale non-NULL running_task and take the wrong code path.
2026-07-21 17:15:20 +03:00
Konstantin Kondrashov 90bfe49549 fix(esp_event): prevent UAF race between post and loop delete (SEC-222)
esp_event_post_to() could access loop->queue / loop->mutex after
esp_event_loop_delete() freed them when both ran concurrently.

Introduce esp_event_loop_state_t with:
- posts_in_flight: reference-count incremented atomically (under
  state.lock spinlock) before touching any loop resources, decremented
  on every exit path via goto on_err.
- deleting: atomic_bool set by esp_event_loop_delete() to block new
  posts from entering the critical section.

esp_event_loop_delete() sets deleting=true, then busy-waits (releasing
and re-acquiring loop->mutex each tick) until posts_in_flight reaches
zero before proceeding with teardown.

esp_event_isr_post_to() performs a lock-free atomic_load of deleting as
a best-effort guard; ISR context cannot participate in the spinlock
protocol but the window is documented and accepted.
2026-07-21 17:15:19 +03:00
Konstantin Kondrashov c0fc78ca26 fix(esp_event): skip dispatch for internal cleanup events (SEC-221)
After processing an esp_event_handler_cleanup sentinel, execution fell
through into the regular dispatch block. Every loop-level (ANY_BASE/
ANY_ID) handler was invoked with base="cleanup" and event_data pointing
at the internal esp_event_remove_handler_context_t struct.

Consequences:
- Information disclosure: internal handler addresses and loop instance
  pointer are exposed to every loop-level handler.
- UAF: if a handler stores event_data for later use, post_instance_delete
  frees the ctx, turning the stored pointer into a dangling reference.
- Logic corruption: handlers that switch on base with a default branch
  misbehave on every unregister anywhere in the system.

Fix: wrap the regular dispatch block in an else clause so it is skipped
entirely for cleanup events. post_instance_delete, ticks accounting, and
xSemaphoreGiveRecursive remain in the shared tail executed for both paths.

Closes SEC_221
2026-07-21 16:51:40 +03:00
Konstantin Kondrashov 086faab0c5 fix(esp_event): use recursive mutex API in handler unregister (SEC-220)
1) loop->mutex is created with xSemaphoreCreateRecursiveMutex(). FreeRTOS
requires that recursive mutexes are only acquired and released with
xSemaphoreTakeRecursive / xSemaphoreGiveRecursive.

esp_event_handler_unregister_with_internal() used the non-recursive
xSemaphoreTake(loop->mutex, 0) / xSemaphoreGive(loop->mutex) in the fast
path. The non-recursive Take bypasses uxRecursiveCallCount bookkeeping;
if the same task subsequently takes the mutex recursively (e.g. re-entry
from a handler or a follow-up register), the call count drifts. The
non-recursive Give then unconditionally drops the holder, allowing another
task to acquire the mutex while the original task still believes it holds
the lock — a full lock violation on the handler list leading to UAF and
potential RCE on attacker-driven event floods.

Fix: replace xSemaphoreTake/xSemaphoreGive with the Recursive variants in
the fast (try-take with timeout 0) path of unregister_with_internal.

2) avoid use-after-free when unregistering handler from a callback

The recursive try-lock introduced in SEC-220 succeeds re-entrantly when a
handler unregisters itself from within its own callback, causing the handler
node to be freed immediately while the dispatch loop still writes profiling
counters to it after the callback returns. Route the in-callback case to the
deferred cleanup path and only free directly once no dispatch is active.

Closes SEC_220
2026-07-21 16:51:40 +03:00
Konstantin Kondrashov a2d865b4c8 fix(esp_event): protect is_handler_registered traversal with mutex (SEC-219)
esp_event_is_handler_registered() walked loop_nodes, base_nodes, id_nodes
and handler lists with no lock held, then released an unowned mutex at the
'out:' label via xSemaphoreGive().

Concurrent register/unregister/delete operations can free handler nodes
during the unlocked walk (SLIST UAF). The xSemaphoreGive on an unowned
recursive mutex corrupts the recursive call-count of any task that
legitimately holds the mutex.

Fix:
- Take loop->mutex with xSemaphoreTakeRecursive before the traversal.
- Replace xSemaphoreGive at the 'out:' label with xSemaphoreGiveRecursive
  so every exit path holds the mutex for exactly one balanced take/give.

Closes SEC_219
2026-07-21 16:51:39 +03:00
Konstantin Kondrashov 2fec4e6930 fix(esp_event): fix format string vulnerability in esp_event_dump (SEC-064)
fprintf(file, buf) is a format-string sink: if any registered event base
or handler name contains "%", fprintf interprets it as a format directive,
causing an information leak or crash.

Replace with fprintf(file, "%s", buf) so the buffer is always treated as
plain text regardless of its content.

Closes SEC_064
2026-07-21 16:51:39 +03:00