Commit graph

126,787 commits

Author SHA1 Message Date
Robert Lubos
98f193dce5 net: lwm2m: Verify URI string length before use in FW pull mode
Verify the URI length provided to lwm2m_pull_context_start_transfer()
before use, otherwise in case the URI string is longer than the buffer,
only part of it was copied w/o NULL terminator, which could lead to
out-of-bound reads and other undefined behavior.

As the string length is now validated, just use strcpy() instead of
memcpy(), no need to copy the whole buffer.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 99a164df5c)
2026-06-10 15:33:36 +03:00
Robert Lubos
bd0ecb0d4d net: tcp: Fix TCP context cleanup during async handshake
In case socket is closed during an async TCP handshake, the TCP context
should be closed immediately, otherwise the connection could be
established after the socket was closed, causing TCP context leak.
To avoid race between socket close and resend timer (i.e. socket being
closed at the same time as the retransmission limit is reached), add
extra state checks before attempting to close the TCP context.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 8588b08808)
2026-06-10 15:33:26 +03:00
Robert Lubos
66eb6cb579 tests: net: socket: tcp: Add test for socket close during async connect
Add a test case which verifies that if a client socket is closed during
an async handshake, the TCP context is properly cleaned up on close,
i.e. it no longer tries to establish the connection.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 4e830615a2)
2026-06-10 15:33:26 +03:00
Oleh Konko
9d4ff6f8d0 bluetooth: l2cap: validate alloc_buf user data
validate the assumptions about buffers returned by alloc_buf() in the
LE CoC receive path.

if the returned buffer does not provide enough user_data space for the
internal segment counter, disconnect and drop the buffer instead of
reading or writing past the metadata area.

also document that alloc_buf() must return a buffer with at least
sizeof(uint16_t) bytes of user_data.

Signed-off-by: Oleh Konko <security@1seal.org>
(cherry picked from commit 09ad7174e9)
2026-06-02 20:18:16 -04:00
Daniel Leung
a78d467d16 xtensa: mpu: fix arch_buffer_validate() if overflow
If the (addr + size) overflows the memory address space,
the inner loop may not run to check for permission. Since
the default return value was 0 (meaning permitted), it
would incorrectly say memory access was okay. Fix this by
changing the default return value to -EINVAL. Only after
the loop of validating the whole input address range then
we set the return value to 0 to say memory access is
permitted. Also check for addition overflow.

Signed-off-by: Daniel Leung <daniel.leung@intel.com>
(cherry picked from commit 3b1bdaf548)
2026-05-28 13:29:23 -04:00
Michael Zimmermann
c691a63bfb drivers: ethernet: adin2111: increase OA buffer size
The comment is correct, the code was wrong. Each chunk can be 64 bytes of
data, but they also have 4 byte headers. So to be able to read 255 chunks
with 64 bytes of data each, The buffer has to be 255 * 68.

Signed-off-by: Michael Zimmermann <michael.zimmermann@sevenlab.de>
(cherry picked from commit c98321cbfe)
2026-05-28 13:28:37 -04:00
Surya Prakash T
c490d0b5b4 fs: fix FUSE open permissions and validate flags
ffa_create_top() was opening files with FS_O_CREATE | FS_O_WRITE
only, which caused host applications like 'cat' to fail with
Permission denied when trying to read the file through FUSE. This
is because FAT filesystem explicitly checks the READ flag before
allowing read access.

Fix by replacing FS_O_WRITE with FS_O_RDWR so the file is opened
with both read and write access.

Signed-off-by: Surya Prakash T <suryat@aerlync.com>
(cherry picked from commit 8f959ad0e6)
2026-05-28 13:27:50 -04:00
Flavio Ceolin
01ac66a105 posix: mqueue: fix integer overflow in mq_open() buffer allocation
The limit check on mq_attr used && instead of ||, so a request
exceeding only one of CONFIG_MSG_SIZE_MAX or CONFIG_POSIX_MQ_OPEN_MAX
was accepted. The buffer was then allocated as
msg_size * max_msgs without overflow checking, allowing the
multiplication to wrap and produce an under-sized heap buffer
that a later mq_send() would overflow.

Reject when either limit is exceeded, and use size_mul_overflow()
before k_malloc().

Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 8a1fe0f6ad)
2026-05-28 13:26:46 -04:00
Chaitanya Tata
33dc0970da drivers: wifi: nrf_wifi: Validate PS event TWT flow count and length
Reject malformed nrf_wifi_umac_event_power_save_info payloads before
copying TWT entries into struct wifi_ps_config. The handler previously
trusted num_twt_flows and indexed twt_flow_info[] without checking
WIFI_MAX_TWT_FLOWS or event_len, which could overflow the fixed Zephyr
twt_flows buffer and read past the event buffer.

Fix issue #108848.

Signed-off-by: Chaitanya Tata <Chaitanya.Tata@nordicsemi.no>
Assisted-by: Cursor:Auto
(cherry picked from commit a2c4324acd)
2026-05-15 22:31:15 +03:00
Jukka Rissanen
b50307e82b tests: net: utils: Enable ASAN
Run address sanitizer to catch any undefined behavior issues
in the code.

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit d5ced71a8c)
2026-05-15 22:31:08 +03:00
Jukka Rissanen
04e4ebc86d tests: net: utils: Check empty value using memcmp()
Use memcmp() to compare values instead of direct comparison.
Without this, some of the tests were failing because this
comparison "" != "" was true when ASAN was enabled.

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 007a274258)
2026-05-15 22:31:08 +03:00
Jukka Rissanen
84f7d91aa9 tests: net: utils: Fix test case having a buffer overflow
The test code accessed buffer outside of limits. Fix it by
setting the string length properly in the test.

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 2df51049e4)
2026-05-15 22:31:08 +03:00
Jukka Rissanen
31255a843d tests: net: utils: Add IPv6 tests for address parser
Make sure that IPv6 address parsing works as expected.

Assisted-by: Claude:claude-sonnet-4.6
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 1c79d0c467)
2026-05-15 22:31:08 +03:00
Jukka Rissanen
e1667a8220 net: utils: Fix possible overflow in IPv6 address parsing
Make sure we will not overflow the ipaddress buffer if
port number is given.

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 6e119a636a)
2026-05-15 22:31:08 +03:00
Jukka Rissanen
8d933bd907 tests: net: utils: Add IPv4 tests for address parser
Make sure that IPv4 address parsing works as expected.

Assisted-by: Claude:claude-sonnet-4.6
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit d1b52d078f)
2026-05-15 22:31:08 +03:00
Jukka Rissanen
c1140c2265 net: utils: Fix possible overflow in IPv4 address parsing
Make sure we will not overflow the ipaddress buffer if
port number is given.

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 1c8d19a51f)
2026-05-15 22:31:08 +03:00
Adam Wojasinski
23d4efd26d net: ptp: Fix undefined bitwise shift in port management
Add bounds checking to PTP management interval parameters to prevent
undefined behavior from bitwise shift operations.

The port_timer_set_timeout() and port_timer_set_timeout_random()
functions perform left and right shift operations using the
log_announce_interval and log_sync_interval values as shift counts.
Without bounds validation, these int8_t parameters could be set to
extreme values (e.g., via PTP management messages) that exceed the
valid shift range, causing undefined behavior.

(C11, 6.5.7p3)
> If the value of the right operand is negative or is greater than
or equal to the width of the promoted left operand,
the behavior is undefined

(C++11, 5.8p1)
> The behavior is undefined if the right operand is negative,
or greater than or equal to the length in bits of the promoted
left operand.

Limit both log_announce_interval and log_sync_interval to the range
[-63, 63] using MIN/MAX macros when accepting values from PTP management
frames. This range is preventing shift operations outside
the 64-bit width used in the timeout calculations.

Fixes: GHSA-3v98-458v-388r

Signed-off-by: Adam Wojasinski <awojasinski@baylibre.com>
(cherry picked from commit 5b32348c1b)
2026-05-15 21:25:33 +03:00
Aleksandr Khromykh
35592afcfe bluetooth: mesh: fix solicitation data length
Commit fixes potential solicitation data length underflow.

Signed-off-by: Aleksandr Khromykh <aleksandr.khromykh@nordicsemi.no>
(cherry picked from commit ed7adfd635)
2026-05-15 21:25:17 +03:00
Flavio Ceolin
54eadd63f0 net: dns: validate rdata length in dns_unpack_answer
dns_unpack_answer() validated only the fixed RR header size and
accepted any rdlength, even one extending past the end of the packet.
TXT and SRV consumers in resolve.c then read up to rdlength bytes from
the message buffer, causing an out-of-bounds read on a truncated or
crafted response.

Reject any RR whose declared rdata extends past dns_msg->msg_size at
the single chokepoint in dns_unpack_answer(), so all current and
future RR consumers are covered.

Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 58b46c81c6)
2026-05-12 21:27:40 +03:00
Michael Zimmermann
5b5264302a drivers: ethernet: adin2111: reset state when the read packet it too big
Add a bounds check to prevent a chunk from being written outside the
buffer.

Signed-off-by: Michael Zimmermann <michael.zimmermann@sevenlab.de>
(cherry picked from commit 158df8d088)
2026-05-12 19:24:04 +03:00
Robert Lubos
8d8d07292e net: ipv6: Fix ND packets validation on input
The checks validating RA, NS and NA packets content on input were not
correct - packets should be dropped in case any of those checks failed,
however current logic was invalid, causing other checks to be ignored as
long as the ICMPv6 code was correct (i. e. 0).

Apart from fixing the logic, split the single convoluted if condition
into separate if checks for better readability.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 095f064c94)
2026-05-12 19:23:44 +03:00
Robert Lubos
106913d464 tests: net: Add few tests for bad ND packets validation
Add a few new tests covering the bug discovered in ND packet
headers validation on input. Packets with invalid hop limit
should be dropped instead of silently being passed through only
if the ICMPv6 code is correct.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 137d08f879)
2026-05-12 19:23:44 +03:00
Jordan Yates
25c4b91f3f samples: net: nsos: remove CONFIG_HEAP_MEM_POOL_SIZE
Remove the explicit setting of `CONFIG_HEAP_MEM_POOL_SIZE` from NSOS
samples, letting the build system construct the heap size from Kconfig
options.

Signed-off-by: Jordan Yates <jordan@embeint.com>
(cherry picked from commit 7e3c5ab2bb)
2026-04-29 15:39:59 +03:00
Jordan Yates
5da895ad7c net: heap default for NSOS DNS results
DNS queries using native posix can return multiple results. Add a
relatively large default to pre-empt failures due to the query being
too successful.

Extra RAM usage can be ignored since NSOS sockets can only exist on
native posix, which has essentially infinite RAM.

Signed-off-by: Jordan Yates <jordan@embeint.com>
(cherry picked from commit 3feb7ca425)
2026-04-29 15:39:59 +03:00
Jordan Yates
d5b80bcee7 net: nsos_sockets: update heap size check
The final system heap size is now stored in `K_HEAP_MEM_POOL_SIZE`, not
`CONFIG_HEAP_MEM_POOL_SIZE`.

Signed-off-by: Jordan Yates <jordan@embeint.com>
(cherry picked from commit 16c2444d7a)
2026-04-29 15:39:59 +03:00
Michael Ellerman
9592f3d269 net: lib: http_server: Reject over length websocket key header
If CONFIG_HTTP_SERVER_MAX_HEADER_LEN is increased from the default of
32, a compiler warning pops in the HTTP websocket code:

    zephyr/subsys/net/lib/http/http_server_http1.c:
    In function 'on_header_value':
    zephyr/subsys/net/lib/http/http_server_http1.c:898:33:
    warning: 'strncpy' output may be truncated copying between 0 and 32
    bytes from a string of length 47 [-Wstringop-truncation]
      898 |          strncpy(ctx->ws_sec_key, ctx->header_buffer,
          |          ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
      899 |                  MIN(sizeof(ctx->ws_sec_key), offset));
          |                  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

This comes from:

                if (ctx->websocket_sec_key_next) {
    #if defined(CONFIG_WEBSOCKET)
                         strncpy(ctx->ws_sec_key, ctx->header_buffer,
                                 MIN(sizeof(ctx->ws_sec_key), offset));
    #endif

If eg. header_buffer is 48 bytes and holds a string >= 32 bytes then
ws_sec_key can end up non-nul terminated. That can then lead to buffer
overflow in handle_http1_to_websocket_upgrade().

Add a check to make sure the header value fits in ws_sec_key, if not
reject the request with a HTTP 500. The websocket key is not expected to
be > 31 bytes.

Once the check is in place, it's safe to use memcpy() for the copy, and
then add the terminating nul manually.

Signed-off-by: Michael Ellerman <mpe@oss.tenstorrent.com>
(cherry picked from commit 5d653fcfd4)
2026-04-29 15:39:59 +03:00
Stephan Linz
e35b80d92d doc: ti: cc3220sf_launchxl: fix conf file reference
With PR #107089 the conf file 'cc3220sf_launchxl.conf' in the WiFi Shell
sample was renamed to 'cc3220sf_launchxl_cc3220sf.conf'.

Signed-off-by: Stephan Linz <linz@li-pro.net>
2026-04-29 15:26:36 +03:00
Sarah Renkhoff
ebca87fefd drivers: entropy: stm32: Lock semaphore before hardware register access
Resuming the device involves hardware accesses including register
writes, so we need to acquire the semaphore lock first to avoid
interference with other cores also using the RNG.

Signed-off-by: Sarah Renkhoff <sarah.renkhoff@gmail.com>
(cherry picked from commit 95ff84434f)
2026-04-27 17:18:47 +03:00
Mathieu Choplain
68a64f4846 drivers: usb: dc: stm32: don't invoke callbacks from ISR context
Modify driver to process interrupts from upper half ISR then signal a
bottom half ISR thread which performs callback invokation. This ensures
callbacks run in thread context which is necessary for proper operation of
various classes.

Signed-off-by: Mathieu Choplain <mathieu.choplain-ext@st.com>
(cherry picked from commit 9ec2cd318f)
2026-04-27 09:22:39 +03:00
Fabrice DJIATSA
36ab2b8d6d drivers: flash: stm32 ospi: use OPI erase opcode in correct mode
The commit c42c8a4da4 (do not invalidate bet at end of loop")
correctly restored the best erase type (bet) selection logic
based on SFDP/JESD216 erase types.
However, this caused a regression
in Octal OPI mode: when bet != NULL, the driver started using bet->cmd
(a standard SPI 1-byte opcode) directly, which is not valid in OPI mode
where the controller expects OPI opcodes (2-byte OCMD).

When bet != NULL:
- In OPI mode, ignore bet->cmd and use the OPI sector erase
opcode SPI_NOR_OCMD_SE.
- In SPI/QPI modes, keep using bet->cmd as intended.

Signed-off-by: Fabrice DJIATSA <fabrice.djiatsa-ext@st.com>
(cherry picked from commit 955f376078)
2026-04-23 23:00:53 +03:00
Martin Gysel
8ac2097523 drivers: flash: stm32 ospi: do not invalidate bet at end of loop
This modification prevents the bet pointer from being nulled at the end
of the loop, which would otherwise render the search for a suitable
erase type ineffective. It also optimize the loop as it omits
unnecessary operations.

Without this change, the erase size defaults to one sector. If the chip
defines fewer than JESD216_NUM_ERASE_TYPES (=4) erase types, this
behavior still works, as the resulting command will correspond to a
sector erase operation. However, if the chip defines all erase types,
the resulting command will be the one specified in the erase type. But
since bet is nulled, the erase size will incorrectly default to the
sector size.

Signed-off-by: Martin Gysel <me@bearsh.org>
(cherry picked from commit c42c8a4da4)
2026-04-23 23:00:53 +03:00
Javier Romera
f9328284d2 logging: fix starvation caused by uncommitted message
Fix a scenario where the logging thread can enter an infinite
loop and starve lower-priority threads when encountering an
uncommitted log message.

If a lower-priority thread is preempted before committing a
message, and a higher-priority thread triggers log processing,
the logging thread may repeatedly attempt to claim it. Since the
message is pending but not committed, z_log_msg_claim() returns
NULL while z_log_msg_pending() remains true, resulting in a
livelock.

Update the log processing logic to avoid looping on uncommitted
messages, allowing lower-priority threads to resume and complete
the commit.

Fixes #101401

Signed-off-by: Javier Romera <lromerajdev@gmail.com>
(cherry picked from commit 5184eac621)
2026-04-21 12:37:15 +03:00
Robert Lubos
9cfdb6c6c6 net: wifi: Fix static SSID logging
When logging statically configured network SSID, use the Kconfig string
instead of a SSID buffer where it was copied to, as the latter is not
guarantee to be NULL terminated.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 4f09d6bcbc)
2026-04-21 12:36:26 +03:00
Robert Lubos
9826ef565a net: wifi: credentials: Verify statically configured SSID and password
In case CONFIG_WIFI_CREDENTIALS_STATIC is used, verify the statically
configured SSID/password lengths to guarantee they don't exceed the
allowed SSID and password character limits and thus overflow credential
buffers.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 90d9d8e12d)
2026-04-21 12:36:26 +03:00
Ofir Shemesh
f1c38f6cbc net: tcp: fix use-after-free in net_tcp_foreach()
net_tcp_foreach() drops tcp_lock before the callback and re-acquires
it afterwards. A concurrent tcp_conn_release() can free the next
node cached by SYS_SLIST_FOR_EACH_CONTAINER_SAFE during this window,
causing the iterator to follow a dangling pointer on the next
iteration.

Move context teardown in tcp_conn_release() inside the tcp_lock
critical section and keep tcp_lock held across the callback in
net_tcp_foreach(). No current callback acquires tcp_lock.

Signed-off-by: Ofir Shemesh <ofirshemesh777@gmail.com>
(cherry picked from commit cd85e0e890)
2026-04-21 11:22:17 +03:00
Jamie McCrae
264a00162e samples: net: wifi: shell: Add missing Kconfig selection
The cc3220sf_launchxl/cc3220sf board doesn't properly select a
Kconfig, therefore fix it

Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
2026-04-21 11:20:57 +03:00
Jamie McCrae
b59a88890f mgmt: mcumgr: grp: fs_mgmt: Fix not checking if write completed
Fixes an issue whereby a write might have partially been successful
but failed due to insufficient space in the storage device by
re-attempting the write again with the offset, and if it still
fails, return an error

Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
(cherry picked from commit f99dbd622e)
2026-04-21 10:12:09 +03:00
Tomi Fontanilles
a4ebdd7f70 modules: mbedtls: add psa_crypto_random.c source file
It's a new source file that was added with Mbed TLS 3.6.6.

Signed-off-by: Tomi Fontanilles <tomi.fontanilles@nordicsemi.no>
2026-04-20 11:01:51 +03:00
Tomi Fontanilles
003e9228bd manifest: mbedtls: update to 3.6.6
Update Mbed TLS from the 3.6.5 to the 3.6.6 version.

Signed-off-by: Tomi Fontanilles <tomi.fontanilles@nordicsemi.no>
2026-04-20 11:01:51 +03:00
Jukka Rissanen
b08ea667c0 net: ipv4: Do packet length checks before starting fragment reassembly
Make sure to check packet length check before starting the
IPv4 fragmentation reassembly process. This way we can drop the
malformed packet without consuming resources.

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 0747bca9e1)
2026-03-31 13:56:13 +03:00
Mathieu Choplain
e187fb5f50 drivers: clock_control: stm32_common: fix wrong register name for LSEDRV
In a few series managed by the common driver, the LSEDRV field is not in
RCC_BDCR but a different register.

Use proper register name when obtaining the shift to ensure a non-zero
driving capability can be used on these series.

Signed-off-by: Mathieu Choplain <mathieu.choplain-ext@st.com>
(cherry picked from commit 0f6b8c19ab)
2026-03-31 13:56:02 +03:00
Bert Abrath
f2529d6a05 drivers: gpio: sam: only call back when interrupt is actually enabled
ISR bits are set on input level or edge changes, regardless of whether an
interrupt is actually enabled on that line. Therefore, we check whether an
interrupt is actually enabled by masking with IMR. If we didn't do this,
some other enabled interrupt firing could also result in a callback for a
disabled interrupt.

Signed-off-by: Bert Abrath <bert.abrath@basalte.be>
(cherry picked from commit fe0ad472cd)
2026-03-31 12:24:10 +03:00
Bas van Loon
3e9c500e33 modules: openthread: Remove deprecated callbacks.
Fixes build when OPENTHREAD_CONFIG_DIAG_ENABLE is enabled due to
removed callbacks.

Signed-off-by: Bas van Loon <bas@arch-embedded.com>
(cherry picked from commit 83597841ff)
2026-03-31 12:23:34 +03:00
Robert Lubos
77bd9975e2 net: sockets: Check for overflows in recvmsg/sendmsg syscalls
When calling zsock_recvmsg()/zsock_sendmsg() system calls, check if
provided msg->msg_iovlen is valid, i.e. does not cause size_t overflow
when calculating memory needed for msg->msg_iov vector.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit b9ad6b17c7)
2026-03-31 12:23:18 +03:00
Jordan Yates
30b61297c1 net: lib: sntp: SNTP_UNCERTAINTY consistent time sources
When comparing time sources for `CONFIG_SNTP_UNCERTAINTY` to validate
the server responses, `dest_ts_us` and `orig_ts_us` need to be
constructed from the same time sources and have the same offsets applied
in order for math operations to be valid.

Fixes #105101

Signed-off-by: Jordan Yates <jordan@embeint.com>
(cherry picked from commit 4a2374c7a1)
2026-03-31 12:22:48 +03:00
Mohamed Moawad
6ef1972b80 arc: mpu: Fix race condition in MPUv6 buffer validation
Add interrupt locking to arc_core_mpu_buffer_validate() to be atomic.

The function iterates through MPU regions using bank selection, which
requires multiple register accesses. Without interrupt protection, an
interrupt or context switch during iteration can corrupt the bank
selection state, causing incorrect region lookups and spurious access
denials.

Signed-off-by: Mohamed Moawad <moawad@synopsys.com>
(cherry picked from commit c0304cb3ba)
2026-03-31 12:22:39 +03:00
Mathieu Choplain
1d20e4cf09 drivers: timer: stm32_lptim: guard behind required nodelabel's existence
Don't allow the LPTIM system clock driver to be enabled if the required
nodelabel `stm32_lp_tick_source` does not exist. This prevents incorrect
usage which could result in non-trivial build failures.

Signed-off-by: Mathieu Choplain <mathieu.choplain-ext@st.com>
(cherry picked from commit 94574740f2)
2026-03-31 12:22:30 +03:00
Mathieu Choplain
1db049984f boards: rakwireless: rak3172: use LPTIM1 as system clock properly
The `stm32_lp_tick_source` nodelabel must be placed on a low-power timer to
use it as system clock timer. This was not done by this board so the
Kconfig was unable to determine which clock source was used, and ultimately
resulting in a build error because option `STM32_LPTIM_TIMEBASE` had no
value.

Fix by adding the missing nodelabel.

Signed-off-by: Mathieu Choplain <mathieu.choplain-ext@st.com>
(cherry picked from commit 75fdc2f848)
2026-03-31 12:22:30 +03:00
Pieter De Gendt
21e9b94826 net: lib: sockets: tls: Validate addrlen before memcpy
Prevent writing data that is larger than the destination struct's size.

Signed-off-by: Pieter De Gendt <pieter.degendt@basalte.be>
(cherry picked from commit bcc4c0bb1e)
2026-03-31 12:22:22 +03:00
Martin Stumpf
169c64e807 mcumgr: Fix 'stat' group error codes
Error codes of group 'stat' were incorrectly labeled as group 'zbasic'.

Signed-off-by: Martin Stumpf <finomnis@gmail.com>
(cherry picked from commit 2ef7ee567e)
2026-03-31 12:22:12 +03:00