Commit Graph

24340 Commits

Author SHA1 Message Date
yinqingzhao 1b03c6ac70 fix(wpa_supplicant): fix race where STA is freed before WPA3 SAE finishes 2026-01-08 20:10:11 +08:00
zhangyanjiao 649fd25d49 fix(wifi/espnow): fixed the espnow set peer rate memory leak 2026-01-05 14:15:13 +08:00
Jiang Jiang Jian 035db94ba7 Merge branch 'bugfix/parse_ftm_responder_v5.1' into 'release/v5.1'
bugfix(wifi): Ensure STA parses the FTM responder capability from the beacon correctly (Backport v5.1)

See merge request espressif/esp-idf!44709
2025-12-31 10:46:13 +08:00
Jiang Jiang Jian ebc1049737 Merge branch 'fix/eh_frame_infinite_loop_v5.1' into 'release/v5.1'
fix(esp_system): prevent .eh_frame-based unwinding from looping indefinitely (backport v5.1)

See merge request espressif/esp-idf!41582
2025-12-31 10:07:32 +08:00
Jiang Jiang Jian 0225da009f Merge branch 'bugfix/sync_security_fix_from_flouride_v5.1' into 'release/v5.1'
fix: synchronized several security-related fixes from Google Fluoride (v5.1)

See merge request espressif/esp-idf!44410
2025-12-31 09:17:50 +08:00
Jiang Jiang Jian 98b3fb7e3d Merge branch 'bugfix/fix_compile_tinycrypt_v5.1' into 'release/v5.1'
fix(nimble): Add missing header file to fix compilation issue (v5.1)

See merge request espressif/esp-idf!43889
2025-12-31 05:33:08 +08:00
Akshat Agrawal e7df43f3fe bugfix(wifi): Ensure STA parses the FTM responder capability from the beacon correctly 2025-12-30 19:16:26 +05:30
Omar Chebib a39b0a4947 fix(esp_system): prevent .eh_frame-based unwinding from looping indefinitely 2025-12-30 10:22:30 +00:00
Jin Cheng 53b48b6bda fix(bt/bluedroid): cleaned the code according to the tool cppcheck 2025-12-30 16:11:13 +08:00
Jin Cheng d61c1734c9 fix(bt/bluedroid): fixed possible OOB read in smp_br_data_received 2025-12-30 16:11:13 +08:00
Jin Cheng 411338192c fix(bt/bluedroid): drop connection when atttempting to disable encryption 2025-12-30 16:11:13 +08:00
Jin Cheng b3e5df7874 fix(bt/bluedroid): fixed an integer overflow bug in attp_build_read_multi_cmd 2025-12-30 16:11:13 +08:00
Jin Cheng 04eb410ebc fix(bt/bluedroid): fixed an integer overflow bug in avdt_msg_asmbl 2025-12-30 16:11:13 +08:00
Jin Cheng e92591a07a fix(bt/bluedroid): fixed an OOB bug in bta_av_setconfig_rej 2025-12-30 16:11:13 +08:00
Jin Cheng d36cb2a2ce fix(bt/bluedroid): fixed an OOB bug in btm_read_rssi_complete 2025-12-30 16:11:13 +08:00
Jin Cheng 3ab391c7ae fix(bt/bluedroid): fixed an OOB bug in btm_delete_stored_link_key_complete 2025-12-30 16:11:13 +08:00
Jin Cheng 3e299a98ec fix(bt/bluedroid): fixed an OOB bug in btm_read_tx_power_complete 2025-12-30 16:11:13 +08:00
Jin Cheng 89464b8a0f fix(bt/bluedroid): fixed an OOB bug in btm_create_conn_cancel_complete 2025-12-30 16:11:13 +08:00
Jin Cheng 3e6a58c3d4 fix(bt/bluedroid): fixed an OOB bug in btm_read_local_oob_complete 2025-12-30 16:11:13 +08:00
Jin Cheng 1ff7ffcaf8 fix(bt/bluedroid): fixed an OOB write in SDP_AddAttribute 2025-12-30 16:11:13 +08:00
Jin Cheng 8db0476935 fix(bt/bluedroid): report failure when not able to connect to AVRCP 2025-12-30 16:11:13 +08:00
Jin Cheng c721860460 fix(bt/bluedroid): fixed buffer overflow in BRSF 2025-12-30 16:11:12 +08:00
Jin Cheng 75ab59be87 fix(bt/bluedroid): added negative length check in process_service_search_rsp 2025-12-30 16:11:12 +08:00
Jin Cheng 71f54659ef fix(bt/bluedroid): fixed OOB read in SDP server continuation length 2025-12-30 16:11:12 +08:00
Jin Cheng fa0e1e7f8d fix(bt/bluedroid): added length check when copy AVDTP packet 2025-12-30 16:11:12 +08:00
Jin Cheng bf33651386 fix(bt/bluedroid): fixed OOB read in AT_SKIP_RESET 2025-12-30 16:11:12 +08:00
Jin Cheng b109d3442d fix(bt/bluedroid): fixed OOB write in bta_hf_client_handle_cind_list_item 2025-12-30 16:11:12 +08:00
Jin Cheng 930863a8f4 fix(bt/bluedroid): added boundary check when reading SDP attribute response packet 2025-12-30 16:11:12 +08:00
Jin Cheng dc8852bb6a fix(bt/bluedroid): fixed potential OOB read in the avrc_pars_vendor_rsp 2025-12-30 16:11:12 +08:00
Jin Cheng 88c149ee65 fix(bt/bluedroid): fixed potential OOB read in the reporting handler
Thanks to Luigino Camastra and Pavel Kohout from Aisle Research as
co-reporters for discovering and reporting this issue.
2025-12-30 16:11:12 +08:00
Jin Cheng 83b7ddc675 fix(bt/bluedroid): fixed a potential overflow about the media payload offset
This variable is uint16_t, and is possible to overflow when the length
of headder extension is larger. Here we compare with the data length to
prevent any exceptions.
2025-12-30 16:11:12 +08:00
Jin Cheng 9eb724a37e fix(bt/bluedroid): fixed p_data null dereference in l2c_csm_open 2025-12-30 16:11:12 +08:00
Jin Cheng a44673dd7f fix(bt/bluedroid): fixed Use-After-Free in btm_sec_[dis]connected 2025-12-30 16:11:12 +08:00
Jin Cheng 6daeef22c5 fix(bt/bluedroid): reject device with same address in legacy paring 2025-12-30 16:11:12 +08:00
Jin Cheng 3dbada70a4 fix(bt/bluedroid): ignore AVCT commands that are too long 2025-12-30 16:11:12 +08:00
Jin Cheng de0ad15aa3 fix(bt/bluedroid): use osi_calloc to zero reserved fields in AVRCP 2025-12-30 16:11:12 +08:00
Jin Cheng 0101b834a3 fix(bt/bluedroid): make sure SDP only start discovery once 2025-12-30 16:11:12 +08:00
Jin Cheng 91b233b783 fix(bt/bluedroid): check event ID if of register notification from remote to avoid OOB write 2025-12-30 16:11:12 +08:00
Jin Cheng a0a11bc6ab fix(bt/blurdoird): check Classic key before cross-key derivation 2025-12-30 16:11:12 +08:00
Jin Cheng 60df7ff885 fix(bt/blurdoird): enable bitpool snity checks 2025-12-30 16:11:12 +08:00
Jiang Jiang Jian 6ebff33277 Merge branch 'bugfix/modem_rf_flag_clear_failed_esp32c6_v5.1' into 'release/v5.1'
fix: clear modem RF flag before PMU sleep to prevent open rf failed on next wake-up V5.1

See merge request espressif/esp-idf!44651
2025-12-30 15:11:08 +08:00
Rahul Tank 4b1263e7bb fix(nimble): Add missing header file to fix compilation issue 2025-12-30 11:44:03 +05:30
Jiang Jiang Jian ac7dabaf5a Merge branch 'bugfix/sae_h2e_nvs_default_v5.1' into 'release/v5.1'
fix(esp_wifi): Set default NVS sae pwe value to SAE_PWE_BOTH for ap and station

See merge request espressif/esp-idf!44650
2025-12-30 12:33:19 +08:00
Jiang Jiang Jian 89fd89af5e Merge branch 'fix/ot_used_wrong_nvs_open_api_v5.1' into 'release/v5.1'
fix(openthread): open nvs from the configured partition (v5.1)

See merge request espressif/esp-idf!44031
2025-12-30 10:37:52 +08:00
Jiang Jiang Jian 4a2973eea6 Merge branch 'change/remove_unused_marco_defines_for_rssi_limit_v5.1' into 'release/v5.1'
change(bt): Mark RSSI threshold-related macros as deprecated(backport v5.1)

See merge request espressif/esp-idf!44517
2025-12-30 10:08:45 +08:00
Shreyas Sheth 1fab1a9306 fix(esp_wifi): Set default NVS sae pwe value to SAE_PWE_BOTH for ap and station 2025-12-29 19:18:16 +05:30
Jiang Jiang Jian 8e542979e4 Merge branch 'bugfix/fix_vendor_ie_and_espnow_issues_v5.1' into 'release/v5.1'
fix vendor ie and espnow issues (v5.1)

See merge request espressif/esp-idf!44635
2025-12-29 21:41:08 +08:00
sibeibei 0666a8df90 fix: clear modem RF flag before PMU sleep to prevent open rf failed on next wake-up 2025-12-29 21:39:15 +08:00
zwx 1f0845e8cb fix(openthread): open nvs from the configured partition 2025-12-29 20:17:35 +08:00
Jiang Jiang Jian 08bd69b3ff Merge branch 'fix/freertos_delete_block_tasks_test_v5.1' into 'release/v5.1'
test(freertos): Added stability fixes to the delete blocked tasks test (v5.1)

See merge request espressif/esp-idf!44489
2025-12-29 20:02:43 +08:00