Commit graph

136,983 commits

Author SHA1 Message Date
Jukka Rissanen
0efe0894ff tests: net: utils: Add IPv4 tests for address parser
Make sure that IPv4 address parsing works as expected.

Assisted-by: Claude:claude-sonnet-4.6
Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit d1b52d078f)
2026-05-19 15:13:25 -05:00
Jukka Rissanen
a1baff787b net: utils: Fix possible overflow in IPv4 address parsing
Make sure we will not overflow the ipaddress buffer if
port number is given.

Signed-off-by: Jukka Rissanen <jukka.rissanen@nordicsemi.no>
(cherry picked from commit 1c8d19a51f)
2026-05-19 15:13:25 -05:00
Etienne Carriere
5682a04338 boards: st: nucleo_wba65ri: don't read HSE trimming OTP from non-secure
Do not read OTP related to HSE trimming when TF-M is embedded since
TF-M does yet not allow non-secure world from accessing SoC OTPs.

Use the default HSE trimming value instead.

Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit 9ee6c03ac7)
2026-05-19 15:12:25 -05:00
Flavio Ceolin
d25aa179c8 net: dns: validate rdata length in dns_unpack_answer
dns_unpack_answer() validated only the fixed RR header size and
accepted any rdlength, even one extending past the end of the packet.
TXT and SRV consumers in resolve.c then read up to rdlength bytes from
the message buffer, causing an out-of-bounds read on a truncated or
crafted response.

Reject any RR whose declared rdata extends past dns_msg->msg_size at
the single chokepoint in dns_unpack_answer(), so all current and
future RR consumers are covered.

Signed-off-by: Flavio Ceolin <flavio@hubblenetwork.com>
(cherry picked from commit 58b46c81c6)
2026-05-19 15:11:35 -05:00
Jordan Yates
ba33b3bd88 modem: cmux: fix flow control for user pipes
Once `rx_full` has been set, the modem is instructed to no longer send
data on that DLCI channel until we notify the modem that the channel is
able to receive more data. This happens in the RX callback which drains
the pipe.

Currently the amount of free space required in the ring buffer to
release the flow control condition is hardcoded to
`CONFIG_MODEM_CMUX_MTU`. While this value is fine for the DLCI1 and
DLCI2 channels (which have buffers created as
`CONFIG_MODEM_CMUX_MTU + N` bytes large), the user pipes with size
`MODEM_CELLULAR_USER_PIPE_BUFFER_SIZES` are typically much smaller. This
lead to the flow control condition never being released on the user
pipe DLCI channels once it was set.

Fix the issue by limiting the threshold to the capacity of the ring
buffer, so that if the buffer is completely empty we will always release
the flow control condition.

Signed-off-by: Jordan Yates <jordan@embeint.com>
(cherry picked from commit 4679c69889)
2026-05-19 15:11:00 -05:00
Mathieu Choplain
e146a86a5c doc: migration: 4.4: add hint on how to set Kconfig values for NUM_IRQS
CONFIG_NUM_IRQS is a promptless symbol so setting it is not trivial. Add a
pointer to the documentation page which explains how to do it in the STM32
section of the 4.4 migration guide related to CONFIG_NUM_IRQS changes.

Signed-off-by: Mathieu Choplain <mathieu.choplain-ext@st.com>
(cherry picked from commit 0ac4d66410)
2026-05-19 15:10:32 -05:00
Ali Hozhabri
7091c4817d west.yml: Update west to point to the recent changes for hal_stm32
Update west.yml to point to the recent changes for hal_stm32/v4.4-branch.

Signed-off-by: Ali Hozhabri <ali.hozhabri@st.com>
2026-05-19 15:09:48 -05:00
Ali Hozhabri
4d472ead28 soc: st: stm32: stm32wb0x: Check the stability of HSE after wake-up
Check the stability of HSE before restarting the execution.

Signed-off-by: Ali Hozhabri <ali.hozhabri@st.com>
(cherry picked from commit bc469ea0ae)
2026-05-19 15:09:48 -05:00
Ali Hozhabri
2ac4c66f0d dts: arm: st: wb0: Increase the minimum residency value to 1.5ms
Increase the minimum residency value to 1.5ms since the minimum threshold
is 1070us and depends on max-hs-startup-time (default value: 780us).
Therefore, a safe margin is 1500us to support other values for
max-hs-startup-time.

Signed-off-by: Ali Hozhabri <ali.hozhabri@st.com>
(cherry picked from commit 418c5d6c8e)
2026-05-19 15:09:48 -05:00
Ali Hozhabri
993d64911f drivers: bluetooth: hci: Calculate the future time correctly
Calculate the future time correctly to avoid negative value for "value_ms".

Register the pm_policy_event when HAL_RADIO_TIMER_SetRadioTimerValue
returns success.

Signed-off-by: Ali Hozhabri <ali.hozhabri@st.com>
(cherry picked from commit 2e933d3fec)
2026-05-19 15:09:48 -05:00
Ali Hozhabri
1cfc7764ee drivers: entropy: Fix repetition and adaptive health test errors for WB09
Handle repetition and adaptive health test errors for STM32WB09 properly.
Resetting Health error flags is not enough. See also RM0505 §14.7.11

Signed-off-by: Ali Hozhabri <ali.hozhabri@st.com>
(cherry picked from commit a2d701976b)
2026-05-19 15:09:48 -05:00
Ali Hozhabri
b7530067f8 drivers: entropy: stm32: Skip low power during TRNG wait in S2RAM
Avoid entering low power mode while waiting for an event to be
generated by TRNG interrupt when CONFIG_PM_S2RAM is set.

Signed-off-by: Ali Hozhabri <ali.hozhabri@st.com>
(cherry picked from commit 59ccf80915)
2026-05-19 15:09:48 -05:00
Ali Hozhabri
ba46454418 drivers: entropy: stm32: Avoid RNG reacquisition
Bypass acquiring RNG when it is already acquired.

Signed-off-by: Ali Hozhabri <ali.hozhabri@st.com>
(cherry picked from commit ba7a20af97)
2026-05-19 15:09:48 -05:00
Etienne Carriere
77d30e97b2 soc: st: stm32: ensure post build is run when TF-M is embedded
Ensure Zephyr post build sequence is run when TF-M is embedded
on a STM32 target since TF-M/STM can install its regression.sh
script which must be processed by running STM postbuild.sh
to be functional.

This change fixes an issue where running 'west build' on an
already built project, or running 'west flash' makes the
regression.sh script to be reinstalled raw from TF-M source tree
(platform/target/ext/stm/...) without being updated trough
postbuild.sh script.

Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit d1eb4ccdc5)
2026-05-19 15:08:31 -05:00
Michael Zimmermann
b8ff819257 drivers: ethernet: adin2111: reset state when the read packet it too big
Add a bounds check to prevent a chunk from being written outside the
buffer.

Signed-off-by: Michael Zimmermann <michael.zimmermann@sevenlab.de>
(cherry picked from commit 158df8d088)
2026-05-13 14:29:22 -05:00
Jamie McCrae
56303a8d55 west.yml: MCUboot synchronization from upstream
Update Zephyr fork of MCUboot to revision:
  6d3b3d2c38ab20c242e5b9abb04d050086383eb2

Brings following Zephyr relevant fixes:

  - 6d3b3d2c Version bump for v2.4.0
  - f58e96a0 bootutil: zephyr: link to `mbedTLS` only when
    `CONFIG_MBEDTLS_BUILTIN`
  - 16996904 bootutil: Fix format string in swap_run function log

Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
2026-05-13 14:28:33 -05:00
Alberto Escolar Piedras
f1e7bd895e tests devicetree api_ext: Add missing kconfig
Enable CONFIG_DAC as this test references the driver DT spec structure
and therefore needs the driver built as it is the one instantiating it.

The test builds in typical platforms because the use of the structure is
being optimized out at build time.
But when this is not the case, the test fails to link.

The issue can be reproduced with for ex.
```
cmake -GNinja -DBOARD=native_sim/native ../tests/lib/devicetree/api_ext/ \
  -DCONFIG_NO_OPTIMIZATIONS=y
ninja
```
But will fail for other boards with the default configuration intree.

Signed-off-by: Alberto Escolar Piedras <alberto.escolar.piedras@nordicsemi.no>
(cherry picked from commit 8d9859e2e9)
2026-05-13 14:28:05 -05:00
Benjamin Cabé
48d4b78ab3 net: fix maybe uninitialized warnings
Fixes a few occurrences of "maybe uninitialized" variables that are
flagged when -Wmaybe-uninitialized is enabled. Seen when running e.g.
./scripts/twister -p mps2/an385 -T tests/net/lib/coap_server/common
in "--coverage" mode.

Signed-off-by: Benjamin Cabé <benjamin@zephyrproject.org>
(cherry picked from commit 2f558a5249)
2026-05-13 14:27:05 -05:00
Michael Zimmermann
19c8a9dd54 drivers: ethernet: adin2111: increase OA buffer size
The comment is correct, the code was wrong. Each chunk can be 64 bytes of
data, but they also have 4 byte headers. So to be able to read 255 chunks
with 64 bytes of data each, The buffer has to be 255 * 68.

Signed-off-by: Michael Zimmermann <michael.zimmermann@sevenlab.de>
(cherry picked from commit c98321cbfe)
2026-05-13 14:26:23 -05:00
Sylvio Alves
02c9fe017f dts: espressif: esp32c2/c3: declare zifencei isa extension
ESP32-C2 and ESP32-C3 implement the zifencei extension (fence.i)
but their device trees declared only "i", "m", "c", "zicsr".

Adding zifencei selects rv32im_zicsr_zifencei/ilp32, the atomic-free
multilib, fixing illegal instruction faults on picolibc paths that
touch stdio locking.

Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit 8c34f6fd9f)
2026-05-13 14:25:35 -05:00
Jamie McCrae
6150a8ec82 mgmt: mcumgr: grp: img_mgmt: Fix non-progressive swap offset erase
Fixes not erasing the first sector when using swap using offset mode

Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
(cherry picked from commit 9da5c07615)
2026-05-13 14:24:32 -05:00
Jamie McCrae
28e1c448ec mgmt: mcumgr: grp: os_mgmt: Fix MPSTAT invalid map
Fixes wrongly having an extra map entry for this response

Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
(cherry picked from commit a64883ef5d)
2026-05-07 17:59:42 -05:00
Reto Schneider
d4cbe0f8bb docs: migration: fix link to Mbed-TLS/TF-PSA migration guide
Without the trailing underscore, the link gets rendered raw, and is not
clickable.

Signed-off-by: Reto Schneider <reto.schneider@husqvarnagroup.com>
(cherry picked from commit 110ba3ec16)
2026-05-07 17:59:06 -05:00
Alperen Sener
4d7a60e500 bluetooth: host: Add missing pending IRK update call for ext adv start
Adds IRK update call to internal bt_le_adv_start_ext. And rename it to
adv_start_ext to prevent confusion with public functions.

There are two paths to start ext advertising:
- bt_le_adv_start can start extended advertising if enabled by calling
internal bt_le_adv_start_ext else it starts legacy advertisements.
- bt_le_ext_adv_start specifically starts extended advertisements.

This commit misses the first path for ext advertisement:
6d137ae015

Signed-off-by: Alperen Sener <alperen.sener@nordicsemi.no>
(cherry picked from commit 246050f7f9)
2026-05-07 17:58:22 -05:00
Jamie McCrae
22e26433f8 mgmt: mcumgr: transport: Fix resetting invalid buffer
Fixes an issue whereby the buffer was not checked to be valid
before resetting it

Signed-off-by: Jamie McCrae <jamie.mccrae@nordicsemi.no>
(cherry picked from commit 6f363ec6f7)
2026-05-07 17:57:47 -05:00
Maureen Helm
482d8fe0e3 drivers: usb: common: stm32: enable ULPI PHY driver for F2/F4 series
The ULPI PHY interface driver (phy_ulpi_itf.c) was only being compiled
for STM32F7X and STM32H7X series, causing build failures on other series
that use external ULPI PHYs, such as STM32F4X boards with ULPI PHYs.

Add missing F2/F4 series to the build condition alongside the existing
F7/H7 series checks. This ensures the ULPI interface driver is compiled
for any F2/F4/F7/H7 board that has a ULPI PHY node in its devicetree.

An alternative approach removing the series checks entirely and just
checking CONFIG_DT_HAS_USB_ULPI_PHY_ENABLED was considered, however
there was a concern that the ULPI interface may have different clock
control bits on other series.

This fixes build failures like "undefined reference to
__device_dts_ord_XXX__stm32_phy" when building for STM32F4 boards with
external ULPI PHYs (e.g., adi_sdp_k1). The build failures were
introduced in commit 8b8321d184.

Assisted-by: Claude:claude-sonnet-4-5
Signed-off-by: Maureen Helm <maureen.helm@analog.com>
(cherry picked from commit 7f777c04e5)
2026-05-07 17:57:18 -05:00
Kate Wang
8df1ac907c drivers: display: co5300: Fix framebuffer address alignment handling
Improve the coordinate and address alignment logic in the CO5300
display driver. The driver now properly aligns the framebuffer
address according to the addr_align property from device tree,
in addition to ensuring coordinates are even values.

Signed-off-by: Kate Wang <yumeng.wang@nxp.com>
(cherry picked from commit 4626c0eb2a)
2026-05-07 17:56:41 -05:00
Ofir Shemesh
f81c7e3847 boards: nxp: add soc-nv-flash child to remaining FlexSPI boards
Add soc-nv-flash child nodes to the six NXP FlexSPI boards
not yet converted: mimxrt595_evk, mimxrt685_evk, vmu_rt1170
(mx25um51345g), and mimxrt1050_evk, mimxrt1060_evk,
mimxrt1062_fmurt6 (hyperflash).

Update FlexSPI NOR and HyperFlash drivers to read
write_block_size from the soc-nv-flash node. Remove
soc-nv-flash.yaml from hyperflash and mx25um51345g
bindings.

Signed-off-by: Ofir Shemesh <ofirshemesh777@gmail.com>
(cherry picked from commit 4e59810ffa)
2026-05-01 16:26:21 -05:00
Robert Lubos
3b46d2bb73 net: ipv6: Fix ND packets validation on input
The checks validating RA, NS and NA packets content on input were not
correct - packets should be dropped in case any of those checks failed,
however current logic was invalid, causing other checks to be ignored as
long as the ICMPv6 code was correct (i. e. 0).

Apart from fixing the logic, split the single convoluted if condition
into separate if checks for better readability.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 095f064c94)
2026-05-01 16:25:23 -05:00
Robert Lubos
7af6d02616 tests: net: Add few tests for bad ND packets validation
Add a few new tests covering the bug discovered in ND packet
headers validation on input. Packets with invalid hop limit
should be dropped instead of silently being passed through only
if the ICMPv6 code is correct.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit 137d08f879)
2026-05-01 16:25:23 -05:00
Hake Huang
fd4072fda0 drivers: ethernet: harden DTCM DMA handling on Cortex-M7
Combine the Cortex-M7 ENET workaround updates into one commit.

- clear CACHE_ENET on i.MX RT11xx Cortex-M7 for ERR050396
- disable ETH_NXP_ENET_USE_DTCM_FOR_DMA_BUFFER by default on Cortex-M7
- keep the final Kconfig condition independent of
  DT_HAS_NXP_ENET1G_ENABLED

This avoids touching the same Kconfig and SoC files in follow-up
commits while preserving the intended behavior for PR #106679.

Validation:
- branch history squashed so workaround files are updated once
  in the series

Signed-off-by: Hake Huang <hake.huang@nxp.com>
(cherry picked from commit a4cd6a3ba4)
2026-05-01 16:24:29 -05:00
Hake Huang
fe01f7dc28 drivers: ethernet: handle ENET RX buffer interrupts
Handle both RX frame and RX buffer interrupts in the NXP ENET driver.
This matches the MCUX HAL interrupt handling and avoids leaving RX work
queued behind an unhandled RX buffer interrupt source.

Validation:
- built samples/net/dhcpv4_client for mimxrt1170_evk@B/mimxrt1176/cm7
  with boards/nxp/mimxrt1170_evk/dts/nxp,enet1g.overlay
- verified MCUX HAL uses RX frame and RX buffer interrupts together

Signed-off-by: Hake Huang <hake.huang@nxp.com>
(cherry picked from commit 99bb98e561)
2026-05-01 16:24:29 -05:00
Sylvio Alves
c185bdf27a samples: espressif: spiram_test: add ESP32-S3 test entries
Add test entries for ESP32-S3 default SPIRAM and octal
80 MHz configurations. Move harness config to common
section to avoid duplication.

Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit d95d79dc93)
2026-05-01 16:19:54 -05:00
Sylvio Alves
ea70de25a2 soc: esp32s3: add IRAM placement for mspi_timing_by_mspi_delay
Place mspi_timing_by_mspi_delay text and rodata in IRAM/DRAM.
This file contains PSRAM and flash timing tuning functions
that must not run from flash during MSPI clock reconfiguration.

Signed-off-by: Sylvio Alves <sylvio.alves@espressif.com>
(cherry picked from commit 31377905f2)
2026-05-01 16:19:54 -05:00
Sarah Renkhoff
e75d81387c drivers: entropy: stm32: Lock semaphore before hardware register access
Resuming the device involves hardware accesses including register
writes, so we need to acquire the semaphore lock first to avoid
interference with other cores also using the RNG.

Signed-off-by: Sarah Renkhoff <sarah.renkhoff@gmail.com>
(cherry picked from commit 95ff84434f)
2026-05-01 16:19:13 -05:00
Abderrahmane JARMOUNI
8405f15ff9 boards: st: st25dv_mb1283_disco: fix display Red/Blue colors swap
After restoring ili9xxx driver original behavior of setting BGR mode
(Red/Blue color channels swap) by default, this panel appears to
require it to be disabled according to testing by the community.
https://github.com/zephyrproject-rtos/zephyr/pull/106859#
issuecomment-4191115676

Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
Signed-off-by: Eve Redero <eve.redero@gmail.com>
(cherry picked from commit b3a1487629)
2026-04-27 20:27:11 -05:00
Abderrahmane JARMOUNI
560ce7653a drivers: display: ili9xxx: fix BGR mode (R/B swap)
commit 9b2593b8c5 has changed the internal
ili9xxx driver color config from setting BGR mode (Blue-Red channels
swap, not pixel format byte-swap) by default, to conditioning it on the
use of PIXEL_FORMAT_BGR_565 (ILI9XXX_PIXEL_FORMAT_BGR565 in devicetree),
but without updating all boards/shields to use
ILI9XXX_PIXEL_FORMAT_BGR565 to preserve their old config.

Then commit 69e353904c replaced
ILI9XXX_PIXEL_FORMAT_BGR565 to PANEL_PIXEL_FORMAT_BGR565.
Later, commit b13d9a0510 renamed
PANEL_PIXEL_FORMAT_BGR565 to PANEL_PIXEL_FORMAT_RGB565X, and defined it
as "Byte swapped version of the PIXEL_FORMAT_RGB_565 format", which is
different from how it was interpreted by ili9xxx devices (B/R channel
swapped format).

The fix for this mess is:
- separate BGR mode (B/R channel swap) setting for ili9xxx from pixel
format,
- restore the initial driver config that sets BGR mode by default, in
order to not break in-tree and out-of-tree panels that relied on that
behavior,
- introduce a DT property that allows disabling BGR mode.

A bonus enhancement is to set BGR mode in ili9xxx driver outside
set_orientation() function, since they are unrelated.

Fixes https://github.com/zephyrproject-rtos/zephyr/issues/105521

Signed-off-by: Abderrahmane JARMOUNI <git@jarmouni.me>
(cherry picked from commit d9b7fcd16f)
2026-04-27 20:27:11 -05:00
Szymon Janc
2b0cb548bc doc: release: Add note about Bluetooth Host qualification
Provide qualification scope summary and link to design listing.

Signed-off-by: Szymon Janc <szymon.janc@codecoup.pl>
(cherry picked from commit 9834ca4ef2)
2026-04-27 20:25:53 -05:00
Etienne Carriere
0c132406ea tests: drivers: rtc: rtc_api: test alarm and calib on ST H7Sxx boards
Enable RTC_ALARM and RTC_CALIBRATION in rtc_api tests for stm32h7s*
based ST boards: stm32h7s78_dk and nucleo_h7s3l8.

Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit 0b3b601e75)
2026-04-27 20:25:04 -05:00
Etienne Carriere
3bcf4a3df8 boards: st: nucleo_h7s3l8: set rtc DT alias
Set rtc DT alias to leverage Zephyr generic RTC support on this board.

Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit 2c33e04d09)
2026-04-27 20:25:04 -05:00
Etienne Carriere
192ae7616f boards: st: stm32h7s78_dk: set rtc DT alias
Set rtc DT alias to leverage Zephyr generic RTC support for this board.

Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit 4c438607eb)
2026-04-27 20:25:04 -05:00
Etienne Carriere
672437df6c drivers: rtc: stm32: H7RS series needs backup domain access to read RTC
Enable STM32 backup domain access on H7RS series when accessing some
RTC alarm configuration registers that otherwise would be read as 0.

Signed-off-by: Etienne Carriere <etienne.carriere@st.com>
(cherry picked from commit bf56fb5142)
2026-04-27 20:25:04 -05:00
Robert Lubos
a546924bde samples: net: http_server: Fix configuration
The HTTP server sample uses server certificate with ecdsa-with-SHA256
signature, the currently configured ciphersuite using RSA signature
is wrong for this sample. Therefore, fix the configuration to use ECDSA
instead.

Also update the maximum eventfd count, the allocation currently fails in
the server.

Signed-off-by: Robert Lubos <robert.lubos@nordicsemi.no>
(cherry picked from commit cc500b036e)
2026-04-27 20:23:06 -05:00
Fabian Blatz
7d9d6a2826 drivers: sdhc: sam_hsmci: Initialize variables in sam_hsmci_request_inner
Initialize `transfer_count`, `is_write`, and `byte_mode` variables to
prevent potential use of uninitialized variables.

Signed-off-by: Fabian Blatz <fabianblatz@gmail.com>
(cherry picked from commit 04cfca3141)
2026-04-27 20:21:29 -05:00
Johannes Berndorfer
b8f02e4cfc drivers: ethernet: esp32: Fix bug in DMA buffer read copy logic.
Fixed a logic bug in the ESP32 Ethernet DMA RX datapath.

See #107201.

Signed-off-by: Johannes Berndorfer <johannes@berndorfer.com>
(cherry picked from commit 2764de5c7d)
2026-04-27 20:20:26 -05:00
Tim Pambor
a96ab665bd net: ipv6: nbr: fix use-after-free
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Use iface argument instead
of calling net_pkt_iface() on a potentially freed packet when
updating packet statistics.

Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit aaed8332a6)
2026-04-27 20:19:24 -05:00
Tim Pambor
1ca470743b net: ipv6: mld: fix use-after-free
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Store the iface before
sending instead of calling net_pkt_iface() on a potentially
freed packet when updating packet statistics.

Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit 3159c53e8e)
2026-04-27 20:19:24 -05:00
Tim Pambor
7954f66b47 net: ip: igmp: fix use-after-free
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Store the iface before
sending instead of calling net_pkt_iface() on a potentially
freed packet when updating packet statistics.

Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit 0223e5e3ec)
2026-04-27 20:19:24 -05:00
Tim Pambor
89b1330c13 net: ip: icmpv6: fix use-after-free
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Store the iface before
sending instead of calling net_pkt_iface() on a potentially
freed packet when updating packet statistics.

Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit 09c8578c66)
2026-04-27 20:19:24 -05:00
Tim Pambor
cd5a63801b net: ip: icmpv4: fix use-after-free
Avoid accessing the packet after sending it, as the driver may
have already unreferenced or freed it. Store the iface before
sending instead of calling net_pkt_iface() on a potentially
freed packet when updating packet statistics.

Signed-off-by: Tim Pambor <tim.pambor@codewrights.de>
(cherry picked from commit 86e21665d4)
2026-04-27 20:19:24 -05:00