Commit graph

126,787 commits

Author SHA1 Message Date
Johan Hedberg
75f67d7667 release: Zephyr 4.3.1 v4.3.1
Set version to 4.3.1.

Signed-off-by: Johan Hedberg <johan.hedberg@silabs.com>
Signed-off-by: Chris Friedt <chris@fr4.co>
2026-06-23 14:47:15 +03:00
Flavio Ceolin
2c3c856e07 doc: release: 4.3: add vulnerabilities fixed for 4.3.1
List of vulnerabilities fixed between 4.3.0 and 4.3.1

Signed-off-by: Flavio Ceolin <flavio@hubble.com>
2026-06-23 13:29:19 +03:00
Chris Friedt
8fee269799 doc: release: 4.3: additional issues fixed
ensure additional issues fixed after 4.3.1-rc1 are added to the release
notes.

Signed-off-by: Chris Friedt <chris@fr4.co>
2026-06-19 15:37:53 -04:00
Daniel Leung
2e47b8409d debug: coredump/shell: check tgt code before using string array
This performs a check of target code using it as index to
retrieve target string via the target code string array.

Signed-off-by: Daniel Leung <daniel.leung@intel.com>
(cherry picked from commit a9226324e8)
2026-06-19 11:25:12 -04:00
Yuan Ye
a04f76f7bb Bluetooth: GATT: Enforce characteristic permissions
When a characteristic declaration is passed instead of a value
attribute, ensure the associated characteristic value attribute
permissions are checked before sending notifications, indications
or multiple notifications.

Signed-off-by: Yuan Ye <1275552818@qq.com>
(cherry picked from commit c3386f92fe)
2026-06-18 19:02:08 -04:00
Lyle Zhu
05bbc63d95 bluetooth: classic: sdp: Fix buffer length check in attribute parsing
Fix insufficient buffer length validation in bt_sdp_parse_attribute().
The original check only verified space for the type byte and attribute
ID, but did not account for the type variable itself that is read from
the buffer immediately after the check.

This could lead to a buffer over-read if the buffer contains exactly
sizeof(uint8_t) + sizeof(attr->id) bytes but not enough for the
additional type field.

Add sizeof(type) to the length check to ensure all required data is
present before parsing.

Signed-off-by: Lyle Zhu <lyle.zhu@nxp.com>
(cherry picked from commit dfac5224ab)
2026-06-18 19:01:29 -04:00
Peter Mitsis
b70212771c logging: Fix z_vrfy_log_filter_set() check
Updates the 'src_id' check in z_vrfy_log_filter_check() so that
negative values are also excluded.

Signed-off-by: Peter Mitsis <peter.mitsis@intel.com>
(cherry picked from commit 56a15114c6)
2026-06-18 19:00:53 -04:00
Jukka Rissanen
08a9fefaa2 net: ip: Mark only cross-interface traffic forwarded
Route handling can legitimately resend a packet on the same
interface when a route lookup or on-link lookup keeps the
original egress interface. Those packets are routed, but they
must not be treated as forwarded traffic.

Set net_pkt_forwarding() only when the matching IPv4 or IPv6
forwarding option is enabled and the selected egress interface
differs from the ingress interface. Apply the same rule in the
generic net_route_packet_if() path so the forwarding flag stays
consistent for both explicit-route and on-link routing cases.

[david.brown: Applied to the IPv6-only code on this branch. It predates
the IPv4 forwarding feature and the route.c -> route_ipv4.c/route_ipv6.c
split, so the change is re-pathed into the monolithic route.c:
net_route_packet() gains the cross-interface decision and the forwarded
hop-limit decrement, and net_route_packet_if() the cross-interface gate,
both gated on CONFIG_NET_ROUTING because
CONFIG_NET_IPV4_FORWARDING/CONFIG_NET_IPV6_FORWARDING do not exist here.
The IPv4-only hunks, route_ipv4.c, and the test-split commit are omitted
as inapplicable to this branch.]

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
Assisted-By: Claude:opus-4.8
Signed-off-by: David Brown <david.brown@linaro.org>
2026-06-18 19:00:26 -04:00
Henrik Brix Andersen
f1cb190f7a drivers: can: bosch: m_can: switch to macro for declaring data struct
Switch to using a macro for declaring the Bosch M_CAN driver data struct
and have the macro statically initialize the k_mutex structures at build
time.

The "lock" mutex can be used by the vendor-specific driver front-ends
before the can_mcan_init() function is called (e.g. for configuring the
Message RAM), which will result in attempts to lock an unitialized k_mutex.

Fixes: #111031

Signed-off-by: Henrik Brix Andersen <henrik@brixandersen.dk>
(cherry picked from commit d393623364)
2026-06-18 15:54:34 +03:00
Lyle Zhu
566523d8a0 bluetooth: host: classic: l2cap_br: Fix conf req/rsp length validation
In `l2cap_br_conf_req()` and `l2cap_br_conf_rsp()`, `buf->len` is used
to validate the minimum packet size. However, `buf->len` may exceed the
actual command data length (the `len` parameter from the L2CAP
signaling header), as the buffer can contain data beyond the current
command.

When the command data length `len` is smaller than the minimum packet
size, but `buf->len` is not less than the minimum packet size, the
validation passes incorrectly. Subsequently, when calculating `opt_len`
(`len - sizeof(*req)`), an underflow occurs duw to the value of type
`uint16_t`, resulting in an out-of-bounds buffer access issue.

Fix by validating against the `len` parameter instead of `buf->len` in
both `l2cap_br_conf_req()` and `l2cap_br_conf_rsp()`, since `len`
reflects the actual command data length.

Signed-off-by: Lyle Zhu <lyle.zhu@nxp.com>
(cherry picked from commit 1d45168337)
2026-06-18 15:54:15 +03:00
Lyle Zhu
4dc715ecd3 bluetooth: classic: rfcomm: fix race condition in session disconnect
Fix a race condition in RFCOMM session disconnection when both local
and peer devices initiate disconnection simultaneously.

Add state check in `rfcomm_session_disconnected()` to only transition
to `DISCONNECTED` state if the session is not already in
`DISCONNECTING` state. This prevents the race condition where both
sides set the session to disconnected, causing the disconnection
process to not complete properly and leaving the L2CAP connection
unreleased.

Without this check, subsequent RFCOMM channel connection requests
would fail due to the invalid session state (the expected state is
`IDLE`, while the actual state is `DISCONNECTED`).

Signed-off-by: Lyle Zhu <lyle.zhu@nxp.com>
Signed-off-by: David Brown <david.brown@linaro.org>
Assisted-By: Claude:fable-5
2026-06-18 15:54:05 +03:00
Daniel Leung
6e36fcfc88 kernel: add kobj NULL check in k_thread_name_copy()
Inside k_thread_name_copy(), we call k_object_find() to find
the associated thread object of the incoming thread. However,
the finder can return NULL if incoming pointer address has
no kobj associated. So we need to check for NULL before
dereferencing k_object to look inside. Since k_object_find()
returns NULL if input object is NULL, there is no need to
specifically test thread pointer for NULL, and only need to
check for the return of k_object_find().

Signed-off-by: Daniel Leung <daniel.leung@intel.com>
(cherry picked from commit 4915839510)
2026-06-18 15:53:53 +03:00
Peter Mitsis
cd9a8c18b7 kernel: pipe: user threads may not re-init pipe
Updates z_vrfy_k_pipe_init() to use K_SYSCALL_OBJ_NEVER_INIT()
instead of K_SYSCALL_OBJ() to prevent a user thread from
re-initializing a pipe. This aligns the pipe initialization
behavior to that of other kernel objects such as message queues.

Signed-off-by: Peter Mitsis <peter.mitsis@intel.com>
(cherry picked from commit 4424aa681e)
2026-06-18 15:53:41 +03:00
Michal Chromec
8f98b830b3 serial: uart_mcux_lpuart: remove call of LPUART_Deinit()
Remove call of LPUART_Deinit() from mcux_lpuart_configure().
LPUART_Deinit() disables the LPUART clocks. If the configuration is not
supported, this may leave the LPUART in an uninitialized state with its
clocks disabled. Any subsequent access to LPUART registers can then
cause a hard fault.

Signed-off-by: Michal Chromec <michal.chromec@nxp.com>
Signed-off-by: David Brown <david.brown@linaro.org>
Assisted-By: Claude:opus-4.8
2026-06-18 15:53:28 +03:00
Peter Mitsis
2b0030dd0f kernel: poll: z_vrfy_k_poll() to free memory
Reworks the K_OOPS(K_SYSCALL_OBJ(...)) logic in z_vrfy_k_poll()
to ensure that the allocated 'events_copy' is freed before the
K_OOPS() is performed.

Signed-off-by: Peter Mitsis <peter.mitsis@intel.com>
(cherry picked from commit 8dc7a37bc7)
2026-06-18 15:53:16 +03:00
Ederson de Souza
42942b2177 pmci: mctp: Allocation issues on I2C+GPIO
The result of `mctp_pktbuf_alloc` wasn't being checked on both
controller and target. While a simple check is enough for the
controller, the target fix is a bit more involved.

As the target was allocating the buffer when it received the length
of the message on its pseudoregister, a buggy controller could write
this more than once, making previous allocations leak. This is solved by
only noting the size of the message written to the pseudoregister, and
doing the allocation when the first byte of the message was received.
This flow also ensures that a buggy controller can't skip sending the
length of the message, as this will result in a zero-sized MCTP packet,
which will be handled by libmctp.

Signed-off-by: Ederson de Souza <ederson.desouza@intel.com>
Signed-off-by: David Brown <david.brown@linaro.org>
Assisted-By: Claude:opus-4.8
2026-06-18 15:53:04 +03:00
Sudarshan Iyengar
40dc7a2858 drivers: spi: dw: add frequency validation in configuration path
Validate the SPI bus frequency supplied via spi_config before it is
used to compute the baud-rate clock divider to prevent the following
faults:

- A zero frequency causes an integer division-by-zero when computing
  the clock divider, resulting in a hardware fault or an undefined
  value being written to the SPI_BAUDR register.

- A frequency exceeding half of the input core clock produces a
  divider value less than the minimum of 2 required by the
  DesignWare SSI databook (section 6.2.2), overclocking the
  peripheral and causing undefined bus behaviour.

Return -EINVAL for a zero frequency and -EINVAL for a frequency
greater than clk_hz / 2, surfacing the error to the caller rather
than silently misconfiguring the hardware.

Assisted-by: Claude:claude-opus-4.6
Signed-off-by: Sudarshan Iyengar <sudarshan.iyengar@alifsemi.com>
(cherry picked from commit 6593588562)
2026-06-18 15:52:53 +03:00
Flavio Ceolin
a1974b19ad tests: http_server: tests for http_server_remove_dot_segments
Cover the path normalization helper used by the HTTP server before
resource lookup: pass-through paths, near-miss segments that must not
be touched (".foo", "..foo", "foo..", "foo/..bar"), single-dot
collapse, "/.." resolution within bounds, root-clamped escapes
("/..", "/../..", "/a/../../b"), and preservation of query/fragment
portions.

Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 17b8550e62)
2026-06-18 15:52:43 +03:00
Flavio Ceolin
8b41f7a360 net: http_server: Normalize URL path before lookup
Add http_server_normalize_url() to resolve '.' and '..' segments in
client->url_buffer once the URL is fully assembled to avoid a remote
client to read files outside the configured web root.

Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit f4a423c985)
2026-06-18 15:52:43 +03:00
Chris Friedt
16ecf0f68a doc: release: 4.3: add issues fixed for 4.3.1 release
Generate the list of issues fixed with the 4.3.1 release via
```shell
./scripts/release/list_backports.py -t ~/.ghtoken -b v4.3-branch \
  -s 2025-11-13
```

Minor cleanup of descriptions and RST tags added.

Signed-off-by: Chris Friedt <chris@fr4.co>
2026-06-18 08:33:42 +03:00
Chris Friedt
7f9379ae34 release: Zephyr 4.3.1-rc1 v4.3.1-rc1
Update the version to 4.3.1-rc1.

Signed-off-by: Chris Friedt <chris@fr4.co>
Signed-off-by: Johan Hedberg <johan.hedberg@silabs.com>
2026-06-13 02:16:31 -04:00
Alberto Escolar Piedras
c95a3b1533 bbram: mcp7940c: emulator: Fix off by 1 stack overflow bug
Fix an out of bounds array read, which causes the test to read
beyond the stack and fail (probably at random).
The issue can be pinpointed building with ASAN.

Signed-off-by: Alberto Escolar Piedras <alberto.escolar.piedras@nordicsemi.no>
(cherry picked from commit ae58840f96)
2026-06-12 14:23:49 -04:00
Flavio Ceolin
d7ebf5cd25 kernel: userspace: fix SMP use-after-free
obj_list traversal held lists_lock, but removals held objfree_lock
(k_object_free) or obj_lock (unref_check). On SMP a concurrent
thread could free the node an iterator had saved as next.

Drop objfree_lock and require lists_lock for every obj_list
modification. k_object_free() now holds it across find+remove;
k_thread_perms_clear() takes it around unref_check().

Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit fdc42fa256)
2026-06-12 14:20:51 -04:00
Emil Gydesen
abb8890e87 Bluetooth: BAP: BA: Move att_buf to inst
Since the Broadcast Assistant implementation may have a
pending request _per_ instance, each instance needs its own
buffer to accomodate that, otherwise we may risk overwriting
data between instances. This follows the design used in the
BAP Unicast Client

Signed-off-by: Emil Gydesen <emil.gydesen@nordicsemi.no>
Signed-off-by: David Brown <david.brown@linaro.org>
Assisted-By: Claude:opus-4.8
2026-06-12 14:19:42 -04:00
Jukka Rissanen
59143bb805 net: tcp: Add NULL check when receiving SYN
Make sure that if the connection is closed but we still received
a SYN packet, we do not try to access already closed connection.

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 74931644b5)
2026-06-12 14:19:20 -04:00
Aleksandr Khromykh
ca154850d8 bluetooth: mesh: defer prov protocol timer reset past validity checks
In prov_msg_recv(), the protocol timer was reset unconditionally at
the top of the function, before the FCS check and before the
ADV_LINK_INVALID check. When the link has been marked invalid (e.g.
after a provisioning failure), any incoming PB-ADV packet with a
passing FCS would still reset the timer, preventing
protocol_timeout() from firing and closing the link via
prov_link_close().

Move k_work_reschedule() to after the ADV_LINK_INVALID check so the
timer is only reset for valid PDUs on an active, non-failed link.
Move the FCS check before the timer reset for the same reason.

Once ADV_LINK_INVALID is set the protocol timer is no longer
extended by incoming packets, and the link is closed by
protocol_timeout() as intended, after which the unprovisioned
device beacon and PB-ADV link acceptance are restored.

Signed-off-by: Aleksandr Khromykh <aleksandr.khromykh@nordicsemi.no>
(cherry picked from commit 3f3c37edf8)
2026-06-12 14:19:03 -04:00
Emil Gydesen
638001f5aa Bluetooth: ISO: Add missing buf->len checks in bt_iso_recv
bt_iso_recv pulls the SDU header (with or without) timestamp,
but did not check the length of `buf` before doing so.

Signed-off-by: Emil Gydesen <emil.gydesen@nordicsemi.no>
(cherry picked from commit 756b16b643)
2026-06-12 14:18:51 -04:00
Nicolas Pitre
3cd49ee25b net_buf: make reference counts atomic
The two reference counts in the net_buf library -- the per-header
`buf->ref` and the per-data-block `*ref_count` byte at the start of
each variable-data allocation -- were manipulated with plain non-atomic
C operators (`++`, `--`, `if (--rc)`, `if (!rc)`).

The documented contract says otherwise. The Network Buffers chapter of
the Zephyr docs (`doc/services/net_buf/index.rst`) states:

    "The buffers have native support for being passed through k_fifo
     kernel objects. Use k_fifo_put and k_fifo_get to pass buffer from
     one thread to another."

    "The reference count can be incremented with net_buf_ref() or
     decremented with net_buf_unref(). When the count drops to zero the
     buffer is automatically placed back to the free buffers pool."

There is no requirement for callers to hold a higher-level lock around
ref/unref. The API is documented as self-synchronizing, and existing
users (notably zbus's msg-subscriber path) rely on exactly that:
a producer clones a buffer N times and hands the clones off to N
subscriber threads via their FIFOs, after which the N+1 holders
independently call `net_buf_unref()` with no surrounding lock.

With non-atomic decrement-and-test, two CPUs can concurrently observe
the same prior value (e.g. 1), both decrement, and both conclude they
were the last reference. Concrete failure modes:

  * `mem_pool_data_unref`: both CPUs call `k_heap_free(pool, ref_count)`
    on the same block. `k_heap_free` is internally serialized, so the
    duplicate free typically corrupts heap metadata silently.

  * `heap_data_unref`: both CPUs call `k_free(ref_count)` on the same
    block. `k_free` reads the owning `struct k_heap *` from the 8 bytes
    immediately preceding `ref_count`. The first call frees the block
    and the heap-hardening fill replaces those 8 bytes with the poison
    pattern (0xcfdfdfdfdfdfdfcf). The second call then dereferences a
    poisoned pointer and faults inside `k_spin_lock` (translation
    fault on the bogus heap address).

  * `net_buf_unref`: two CPUs racing the per-header decrement-and-test
    can both decide "I am the last reference," both proceed to
    `net_buf_destroy()`, and the buffer is returned to the pool's LIFO
    twice -- silently corrupting the free list.

Fix: use atomic operations on both reference counts.

The per-data-block refcount changes from `uint8_t` to `atomic_t`. This
fits inside the existing `GET_ALIGN(pool)` reservation (>= sizeof(void
*)) at no memory cost.

The per-header `buf->ref` is overlaid in a union with three small
adjacent uint8_t fields (`flags`, `pool_id`, `user_data_size`) and an
`atomic_t ref_word` view of the same storage:

    union {
        atomic_t ref_word;
        struct {
            uint8_t ref;
            uint8_t flags;
            uint8_t pool_id;
            uint8_t user_data_size;
        };
    };

(Byte order conditional on endianness so `ref` is always the LSB of
`ref_word`; on big-endian 64-bit, the byte struct is shifted by 4
bytes of padding for the same reason.)

Net_buf internals issue `atomic_inc(&buf->ref_word)` /
`atomic_dec(&buf->ref_word)` and narrow the returned word value to
`uint8_t` to extract the ref byte. Because the ref count is bounded
to 254 (already implicit in its uint8_t domain), atomic_inc/dec
adjusts only the LSB; the other three bytes are untouched. Plain
uint8_t reads of `buf->ref` from non-atomic call sites continue to
work, so the change is transparent to the dozens of consumers that
read it for diagnostics.

`flags`, `pool_id` and `user_data_size` are written exactly once at
allocation time on a single thread (or, for `flags`, from a context
that owns the buf exclusively such as bt_buf_make_view on a fresh
view), so there are no concurrent byte writes that could conflict
with the atomic word update. struct net_buf does not grow on either
32-bit or 64-bit: on 32-bit the four bytes are exactly `sizeof(long)`,
on 64-bit they fit in alignment padding the next field already
required.

A BUILD_ASSERT in lib/net_buf/buf.c documents the
`atomic_t == long` assumption that the conditional padding relies on.

In `net_buf_unref`, the per-header refcount and the fields needed for
the debug log (`buf->pool_id`) are captured into local variables
*before* the atomic decrement -- once the reference is dropped, another
CPU may immediately free the buffer, so the buffer must not be read
again. The post-decrement diagnostic log uses the value returned by
`atomic_dec` rather than re-reading `buf->ref`. The `pool->avail_count`
sanity check uses the value returned by `atomic_inc` to avoid a
follow-up `atomic_get` of memory another CPU may have changed.

`net_pkt_frag_unref()` previously had the racy
`if (frag->ref == 1U) alloc_del(); net_buf_unref();` pattern; it is
restructured to do the atomic decrement here and slot the tracker call
in atomically with the "I'm the last reference" decision, with
`net_pkt_frag_del()` routed through it.

This bug had been latent. On real SMP hardware the race window is very
small and the typical net_buf consumers (Bluetooth, networking) tend
to use fixed-data pools (`fixed_data_unref` is a no-op). The race
manifests reliably under FVP, where the FastModel's quantum-based
execution model can schedule N threads to all reach the unref point in
the same simulated moment. We discovered it through the zbus
`msg_subscriber_dynamic_isolated` sample, which exchanges shared data
buffers among 16+ subscribers running on 4 SMP cores.

Signed-off-by: Nicolas Pitre <npitre@baylibre.com>
(cherry picked from commit 9bb2878319)
2026-06-12 13:01:24 +03:00
Jordan Yates
3966669b5c net: sntp: fix close-while-polling in sntp_close_async
Fix `sntp_close_async` closing the socket while the socket service is
still polling it by deferring the close operation to the socket service.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2026-06-12 13:01:12 +03:00
Jordan Yates
2974074f39 net: socket_service: API to unregister and close socket
Closing a socket while it is being polled by another thread is
discouraged and should be avoided. This results in a problem when
attempting to unregister a service via `net_socket_service_unregister`,
the caller has no way of knowing when the socket service has stopped
polling on the socket and it is safe to close.

Solve this issue by introducing `net_socket_service_close`, which
signals the socket service to automatically close the sockets associated
with the service when it stops polling them.

Signed-off-by: Jordan Yates <jordan@embeint.com>
2026-06-12 13:01:12 +03:00
Flavio Ceolin
ab3d5ebc04 fs: ext2: validate directory entry structure before traversal
ext2_fetch_direntry() trusted the on-disk de_rec_len and de_name_len,
and the lookup and readdir paths advanced traversal by an unvalidated
de_rec_len. A crafted ext2 image could trigger an out-of-bounds read
past the directory block buffer or a zero-progress loop in any path
that walks a directory.

Validate rec_len and name_len in the parser, and reject entries whose
header does not fit in the remaining block or whose rec_len would
cross the block boundary in each caller.

Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 7cdb534a3c)
2026-06-12 13:01:00 +03:00
Egill Sigurdur
30e05cdbb5 net: dns: fix string read out of bounds
Fix issue that would be trapped by the address sanitizer, would always
read 7 bytes even though ptr might be shorter, and would therefore
read out of bounds if e.g. the string ".org" was passed.

Signed-off-by: Egill Sigurdur <egill@egill.xyz>
(cherry picked from commit 448a21da12)
2026-06-12 13:00:48 +03:00
Emil Gydesen
727fe24d81 Bluetooth: BAP: Fix issues with qos pointers
In some cases the stream->qos pointer pointed to the
qos argument, and sometimes it pointed to the ep->qos.

Now all qos arguments are copied to ep->qos, and
stream->qos always points to stream->ep.qos.

Some modules had some refactoring done to properly store
the QoS. The unicast client had some additional checks
done or redone, and some now-unused code removed.

Signed-off-by: Emil Gydesen <emil.gydesen@nordicsemi.no>
Assisted-By: Claude:opus-4.8
Signed-off-by: David Brown <david.brown@linaro.org>
2026-06-11 10:24:32 +03:00
Adam Szewczyk
a0562da7a3 net: dns: resolve: avoid timeout-bound alloc in cancel helper
Cancellation can run on timeout paths where a context-based buffer
allocation timeout can expire immediately.

- allocate the temporary packed-name net_buf with K_FOREVER
- keep existing ENOMEM handling for pool exhaustion

Assisted-by: Codex:gpt-5.3-codex
Signed-off-by: Adam Szewczyk <a.szewczyk@cthings.co>
2026-06-11 10:24:20 +03:00
Adam Szewczyk
9d85f6e02b net: sockets: getaddrinfo: cancel timed-out DNS query before retry
Cancel each timed-out DNS request before retrying and reset the local
semaphore state between attempts. This prevents stale delayed callbacks
from touching stack-backed getaddrinfo state after timeout progression.

Assisted-by: Codex:gpt-5.3-Codex
Signed-off-by: Adam Szewczyk <a.szewczyk@cthings.co>
2026-06-11 10:24:20 +03:00
Ryan Erickson
c0dae75a6c drivers: serial: pl011: fix CTS loop
If CTS hardware flow control is in use, prevent an
infinite loop of callbacks.

Enable the CTS interrupt if TX is unavailable from
CTS blocking.

Signed-off-by: Ryan Erickson <ryan.erickson@ezurio.com>
(cherry picked from commit 68e702294b)
2026-06-11 10:24:03 +03:00
Lyle Zhu
9da48dd3f9 bluetooth: classic: hfp_hf: Fix out-of-bounds access in indicator index
Add validation to ensure the indicator index is within the valid range
of the ind_table array before accessing it in cind_handle_values().

Without this check, an out-of-bounds index could lead to buffer overrun
when the index is used to access hf->ind_table array elements later in
the function.

Signed-off-by: Lyle Zhu <lyle.zhu@nxp.com>
(cherry picked from commit cf7693a826)
2026-06-11 10:23:52 +03:00
Shuai Ma
31a9114279 fs: avoid leaking backend file on truncate failure
Problem:
When fs_open() is called with FS_O_TRUNC, the FS backend
opens the underlying file via mp->fs->open() before the
truncate is attempted. If mp->fs->truncate() then fails,
the previous code cleared zfp->mp and returned right away,
which causes two issues:
  - the backend's close hook is never invoked, so the
    resources allocated during open (file slab entries,
    internal caches, backend-specific structures such as
    lfs_file, etc.) stay permanently allocated;
  - a follow-up fs_close(zfp) cannot recover them either,
    because zfp->mp has already been NULL'd and fs_close()
    returns early.

The leak is reproducible on every backend (LittleFS, FAT,
...) and accumulates one slot per failed call until the
file slab is exhausted.

Solution:
Close the backend file explicitly in the truncate failure
path, before clearing zfp->mp, so the FS-specific close
hook can release everything it allocated during open().
If close itself fails, log the secondary error but still
return the original truncate error code, since that is
the root cause callers diagnose against.

Signed-off-by: Shuai Ma <malin719426@gmail.com>
(cherry picked from commit 66ee97f4d9)
2026-06-11 10:23:42 +03:00
Flavio Ceolin
38fc4bd369 Bluetooth: Controller: Fix OOB read in ISOAL
When sc=0, a framed ISO PDU segment header includes a 3-byte time_offset
field, so seg_hdr->len must be at least PDU_ISO_SEG_TIMEOFFSET_SIZE.
isoal_check_seg_header() accepted segments with sc=0 and len<3 as valid,
allowing isoal_rx_framed_consume() to underflow, causing an
out-of-bounds read of up to 255 bytes of adjacent memory into an HCI ISO
packet delivered to the host.

Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 28080d80fc)
2026-06-11 10:23:30 +03:00
Lingao Meng
f342279a54 Bluetooth: Mesh: fix PrivateBeaconKey PSA key leak on subnet delete
subnet_keys_destroy() guarded the destroy of keys->priv_beacon with
#if defined(CONFIG_BT_MESH_V1d1), while net_keys_create() guards the
matching import with #if defined(CONFIG_BT_MESH_PRIV_BEACONS).

Commit 981c79b7ce ("Bluetooth: Mesh: Drop explicit support for
Bluetooth Mesh 1.0.1") removed the CONFIG_BT_MESH_V1d1 Kconfig but
left this stray reference behind. With V1d1 gone, the destroy branch
is permanently dead code, so every successful net_keys_create() leaks
one PSA key slot.

In a long-running test that repeatedly provisions and resets a node
(no persistent settings, in-RAM CDB only), the leak accumulates one
PSA volatile-key slot per provisioning round. With the default
CONFIG_MBEDTLS_PSA_KEY_SLOT_COUNT=16, bt_mesh_private_beacon_key()
fails after ~12 rounds with:

  <err> bt_mesh_net_keys: Unable to generate private beacon key
  <err> bt_mesh_net: Failed creating subnet
  <err> bt_mesh_main: Failed to create network

Align the destroy guard with the import guard so the leak goes away.

Signed-off-by: Lingao Meng <menglingao@xiaomi.com>
(cherry picked from commit f573da9f53)
2026-06-10 15:34:48 +03:00
Philipp Steiner
3bde646e40 net: sockets: fix inet recvmsg ancillary buffer accounting
Use NET_CMSG_SPACE() when checking ancillary buffer capacity and
account for aligned cmsg storage in msg_controllen.

This keeps recvmsg() control-data handling consistent with cmsghdr
layout and avoids under-reporting consumed control-buffer space.

Signed-off-by: Philipp Steiner <philipp.steiner1987@gmail.com>
2026-06-10 15:34:27 +03:00
Tim Pambor
3cab817046 net: ipv6: nbr: fix use-after-free
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Use iface argument instead
of calling net_pkt_iface() on a potentially freed packet when
updating packet statistics.

Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit aaed8332a6)
2026-06-10 15:34:13 +03:00
Tim Pambor
67c8b80901 net: ipv6: mld: fix use-after-free
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Store the iface before
sending instead of calling net_pkt_iface() on a potentially
freed packet when updating packet statistics.

Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit 3159c53e8e)
2026-06-10 15:34:13 +03:00
Tim Pambor
fa0203625d net: ip: igmp: fix use-after-free
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Store the iface before
sending instead of calling net_pkt_iface() on a potentially
freed packet when updating packet statistics.

Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit 0223e5e3ec)
2026-06-10 15:34:13 +03:00
Tim Pambor
5ec8f40568 net: ip: icmpv6: fix use-after-free
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Store the iface before
sending instead of calling net_pkt_iface() on a potentially
freed packet when updating packet statistics.

Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit 09c8578c66)
2026-06-10 15:34:13 +03:00
Tim Pambor
825dd0fabc net: ip: icmpv4: fix use-after-free
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Store the iface before
sending instead of calling net_pkt_iface() on a potentially
freed packet when updating packet statistics.

Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit 86e21665d4)
2026-06-10 15:34:13 +03:00
Jay Beavers
c77b576bf2 usb: device_next: cdc_ncm: Check usbd_ep_enqueue() return value
The cdc_ncm_send() function ignores the return value from
usbd_ep_enqueue(). If the enqueue fails, the code proceeds to block
forever on k_sem_take() waiting for a completion callback that will
never arrive, causing a deadlock.

This was discovered by comparing the CDC-NCM implementation with
CDC-ECM, which correctly checks the return value:

    ret = usbd_ep_enqueue(c_data, buf);
    if (ret) {
        LOG_ERR("Failed to enqueue net_buf for 0x%02x", ep);
        net_buf_unref(buf);
        return ret;
    }

The NCM driver was missing this error handling, leading to potential
hangs if usbd_ep_enqueue() fails for any reason (e.g., endpoint not
ready, USB disconnected, buffer issues).

Fix by checking the return value and properly cleaning up (freeing
the buffer) before returning the error code to the caller.

Signed-off-by: Jay Beavers <jay@tolttechnologies.com>
(cherry picked from commit 255bccc1ba)
2026-06-10 15:34:01 +03:00
Sofian Elmotiem
43e6193d8f kernel/pipe: fix swap_data corruption when k_pipe_read is called from ISR
In ISR context _current is the interrupted thread, not the ISR itself.
Setting _current->base.swap_data from an ISR corrupts a field that
belongs to that thread and may be in active use.

ISR callers must use K_NO_WAIT and never pend, so they never need the
direct-copy buffer. Moving the swap_data assignment into wait_for()
after the K_NO_WAIT early-return ensures it is only set on the path
that will actually pend, which is never the ISR path.

Fixes: #110077

Signed-off-by: Sofian Elmotiem <sofianelmotiem@gmail.com>
(cherry picked from commit f77f55fb16)
2026-06-10 15:33:49 +03:00
Robert Lubos
bfea2140a1 net: lwm2m: Add include guard in lwm2m_pull_context.h
Include guard was missing in lwm2m_pull_context.h internal header.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 55be451592)
2026-06-10 15:33:36 +03:00
Robert Lubos
638ede8f64 net: lwm2m: Align URI size in FW object with FW pull helper
Use the same size for the URI buffer in the FW object implementation as
in the FW pull download helper module. That way, if the server writes
too long URI to handle in the FW pull mode, it'll get an error response
immediately instead of failing at firmware download start.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit b96deb12ad)
2026-06-10 15:33:36 +03:00