Skip to content

Releases: zephyrproject-rtos/zephyr

Zephyr 4.4.2

Choose a tag to compare

@github-actions github-actions released this 07 Aug 15:36
v4.4.2

This is a bugfix release for Zephyr 4.4.1.

Security Vulnerability Related

  • CVE-2026-7007 Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image
  • CVE-2026-8023 Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read
  • CVE-2026-9728 Under embargo until 2026-08-23
  • CVE-2026-9771 Under embargo until 2026-08-16
  • CVE-2026-10593 Remotely triggerable NULL-pointer dereference in Bluetooth LE Audio BAP unicast client QoS-state handling
  • CVE-2026-10635 Dangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code on memory-domain de-init
  • CVE-2026-10641 Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values)
  • CVE-2026-10642 Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control
  • CVE-2026-10643 Out-of-bounds heap write in Zephyr recvmsg() ancillary-data path (insert_pktinfo undersizes the control-buffer capacity check)
  • CVE-2026-10644 Out-of-bounds write in Microchip SERCOM-G1 (PIC32CM-JH) async UART RX with 1-byte buffer
  • CVE-2026-10646 Use-after-return in zsock_getaddrinfo() when a timed-out DNS query is retried without cancellation
  • CVE-2026-10647 Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure
  • CVE-2026-10651 Out-of-bounds read in Bluetooth Classic SDP attribute parsing (bt_sdp_parse_attribute)
  • CVE-2026-10653 Non-atomic net_buf reference counts cause double-free / free-list corruption under concurrent unref
  • CVE-2026-10654 RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic
  • CVE-2026-10655 Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it
  • CVE-2026-10657 Out-of-bounds read in Zephyr DNS resolver mDNS suffix check (memcmp past string NUL)
  • CVE-2026-10658 Out-of-bounds access in Bluetooth ISO receive (bt_iso_recv) due to missing SDU-header length validation
  • CVE-2026-10659 NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resume
  • CVE-2026-10660 Shared reassembly buffer in Bluetooth BAP Broadcast Assistant enables cross-connection memory corruption
  • CVE-2026-10663 Use-after-free / double-free of the root USB device in the experimental USB host stack
  • CVE-2026-10665 Heap buffer overflow on WireGuard receive path via unbounded incoming packet length
  • CVE-2026-10667 SMP use-after-free in Zephyr CONFIG_USERSPACE dynamic kernel-object tracking, reachable from unprivileged user threads
  • CVE-2026-10668 Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver
  • CVE-2026-10670 User-triggerable kernel NULL-pointer dereference (DoS) in k_thread_name_copy() syscall verifier
  • CVE-2026-10671 User thread can re-initialize an in-use k_pipe, corrupting kernel wait queues (CONFIG_USERSPACE)
  • CVE-2026-10674 DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled
  • CVE-2026-10675 Bluetooth Mesh PB-ADV: invalidated provisioning link kept alive indefinitely, blocking (re)provisioning (DoS)
  • CVE-2026-10677 Kernel heap memory leak in z_vrfy_k_poll() lets an unprivileged user thread exhaust the kernel resource pool
  • CVE-2026-10678 NULL-pointer / out-of-bounds write in Zephyr MCTP I2C+GPIO target binding driven by an unauthenticated I2C controller
  • CVE-2026-10679 Divide-by-zero in DesignWare SPI driver reachable from spi_transceive syscall (local DoS)
  • CVE-2026-10680 Out-of-bounds access in Zephyr BR/EDR L2CAP configuration request handling via uint16_t length underflow
  • CVE-2026-10681 SMP race in thread_idx_alloc() lets concurrent k_object_alloc(K_OBJ_THREAD) callers share a kernel-object permission slot
  • CVE-2026-10682 Out-of-bounds write in Zephyr log_filter_set syscall verifier reachable from userspace
  • CVE-2026-10683 DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS)
  • CVE-2026-10685 Under embargo until 2026-07-31
  • CVE-2026-10686 Under embargo until 2026-07-31
  • CVE-2026-10772 Under embargo until 2026-08-01
  • CVE-2026-10773 Under embargo until 2026-08-01
  • CVE-2026-10774 Under embargo until 2026-08-02
  • CVE-2026-10848 Under embargo until 2026-08-02
  • CVE-2026-10849 Under embargo until 2026-08-03
  • CVE-2026-11368 Under embargo until 2026-08-04
  • CVE-2026-11742 Under embargo until 2026-08-07
  • CVE-2026-11743 Under embargo until 2026-08-07
  • CVE-2026-11809 Under embargo until 2026-08-08
  • CVE-2026-11810 Under embargo until 2026-08-08
  • CVE-2026-11811 Under embargo until 2026-08-08
  • CVE-2026-11812 Under embargo until 2026-08-08
  • CVE-2026-11893 Under embargo until 2026-08-09
  • CVE-2026-11894 Under embargo until 2026-08-09
  • CVE-2026-11985 Under embargo until 2026-08-09
  • CVE-2026-12051 Under embargo until 2026-08-10
  • CVE-2026-12052 Under embargo until 2026-08-10
  • CVE-2026-12233 Under embargo until 2026-08-11
  • CVE-2026-12234 Under embargo until 2026-08-11
  • CVE-2026-12236 Under embargo until 2026-08-13
  • CVE-2026-12364 Under embargo until 2026-08-14
  • CVE-2026-12519 Under embargo until 2026-08-16
  • CVE-2026-12520 Under embargo until 2026-08-16
  • CVE-2026-12521 Under embargo until 2026-08-16
  • CVE-2026-12522 Under embargo until 2026-08-16
  • CVE-2026-12629 Under embargo until 2026-08-16
  • CVE-2026-12630 Under embargo until 2026-08-16
  • CVE-2026-12631 Under embargo until 2026-08-16
  • CVE-2026-12632 Under embargo until 2026-08-16
  • CVE-2026-12633 Under embargo until 2026-08-16
  • CVE-2026-12999 Under embargo until 2026-08-22
  • CVE-2026-13213 Under embargo until 2026-08-23
  • CVE-2026-13214 Under embargo until 2026-08-23
  • CVE-2026-13215 Under embargo until 2026-08-23
  • CVE-2026-13217 Under embargo until 2026-08-23
  • CVE-2026-13478 Under embargo until 2026-08-25
  • CVE-2026-13479 Under embargo until 2026-08-26
  • CVE-2026-13480 Under embargo until 2026-08-26
  • CVE-2026-13481 Under embargo until 2026-08-26
  • [CVE-2026-13734](h...
Read more

Zephyr LTS v3.7.3-rc1

Zephyr LTS v3.7.3-rc1 Pre-release
Pre-release

Choose a tag to compare

@nashif nashif released this 06 Aug 00:38
v3.7.3-rc1

This is an LTS maintenance release with fixes.

Security Vulnerability Related

The following CVEs are addressed by this release:

More detailed information can be found in: https://docs.zephyrproject.org/latest/security/vulnerabilities.html

Read more

Zephyr v4.4.2-rc1

Zephyr v4.4.2-rc1 Pre-release
Pre-release

Choose a tag to compare

@MaureenHelm MaureenHelm released this 29 Jul 20:54
v4.4.2-rc1

Issues fixed

These GitHub issues were addressed since the previous 4.4.1 tagged release:

  • #103831 - Add mcxc242 lpuart dma support (async api)
  • #104900 - Bluetooth LE host qualification for 4.4 release
  • #104922 - drivers: nuvoton: hs usbd: control cmds stuck naking
  • #106334 - Thread-safety race condition in net_buf_unref
  • #107374 - ESP32 S3 doesn't boot if CONFIG_ESP32_WIFI_NET_ALLOC_SPIRAM is combined with CONFIG_SPI
  • #107633 - USB-Next: CDC-ACM: Incomplete transmission on MCUmgr
  • #108120 - STM32WBAx : Flash process request is not handled
  • #108637 - tests/drivers/bbram/generic/ fails at random due to drivers/bbram/bbram_microchip_mcp7940n_emul.c
  • #108793 - kernel: init: main thread not tagged K_FP_REGS when CONFIG_FPU && CONFIG_FPU_SHARING
  • #109128 - fs: backend file resource leak when fs_open with FS_O_TRUNC fails during truncate
  • #109383 - stm32wbax: bluetooth: issue when extended Advertising Data Packet length exceeds 250 bytes
  • #109403 - net: icmpv6: missing source address guard in net_icmpv6_send_error (RFC 4443 2.4(e.6))
  • #109460 - entropy: psa: ENTROPY_PSA_CRYPTO_RNG deprecated without migration path
  • #109602 - espressif: esp32c5/esp32s3: fix PSRAM + Wi-Fi heap mapping and linker segment sizing bugs
  • #109641 - west spdx fails on Windows if project is on a different drive
  • #109907 - tests: dma: chan_blen_transfer: test case is not synchronized with transfer callback
  • #110018 - drivers: gpio: esp32: GPIO deep sleep wakeup requires CONFIG_PM
  • #110077 - k_pipe_read in ISR causing fault
  • #110303 - Bluetooth: Mesh: PrivateBeaconKey PSA key leak after subnet deletion
  • #110643 - drivers: stepper: adi_tmc: tmc51xx configure_ramp appears to use child device for clock lookup
  • #110645 - net: sockets: recvmsg() ancillary-data capacity check undercounts cmsg size
  • #110651 - usb: device_next: cdc_ncm: TX thread deadlocks when usbd_ep_enqueue() fails
  • #110654 - drivers: can: nxp: flexcan: bus errors when transmitting leads to log flooding
  • #110749 - drivers: uart: sercom g1: async RX of a 1-byte buffer writes one byte past the buffer
  • #110757 - xtensa: ptables: deinitialized memory domain is left on the global domain list
  • #110762 - bluetooth: classic: hfp_hf: cind_handle_values() writes past ind_table on a long +CIND list
  • #110766 - drivers: serial: pl011: TX enable spins forever when CTS flow control blocks transmission
  • #110771 - net: sockets: getaddrinfo() retry after a DNS timeout leaves the previous query in flight and touches stale stack state
  • #110775 - Bluetooth: BAP: unicast client dereferences NULL stream->qos when a QoS Configured notification arrives before the stream is added to a group
  • #110849 - bluetooth: classic: sdp: bt_sdp_parse_attribute() reads one byte past the buffer end
  • #110854 - bluetooth: classic: rfcomm: session stuck and L2CAP channel leaked when both sides disconnect simultaneously
  • #110857 - net: sntp: close-while-polling use-after-free in sntp_close_async
  • #110866 - net: dns: .local suffix check reads past the end of the hostname string
  • #110915 - pb-adv bearer resets the protocol timer unconditionally
  • #110954 - drivers: disk: ftl: dhara callbacks write through NULL error pointer on flash error
  • #110956 - Bluetooth: ISO: bt_iso_recv() pulls the SDU header without checking buf->len
  • #110967 - Bluetooth: BAP: Broadcast Assistant shares one att_buf across all connections
  • #111016 - kernel: userspace: dynamic kernel-object list freed under a different lock than it is traversed
  • #111020 - usb: host: ctx->root left dangling after root device disconnect
  • #111031 - tests/drivers/can/api/drivers.can.api fails on mutex
  • #111032 - tests/net/lib/tls_credentials/net.tls_credentials.trusted_tfm fails on mutex
  • #111056 - Wireguard replay issue
  • #111082 - net: wireguard: incoming data packet can overflow the linearization buffer
  • #111087 - kernel: k_thread_name_copy() syscall dereferences NULL for an unregistered thread pointer
  • #111100 - kernel: pipe: a user thread can re-initialize a pipe that is already in use
  • #111110 - kernel: poll: z_vrfy_k_poll() leaks events_copy when a k_poll_event carries an invalid object handle
  • #111116 - pmci: mctp: I2C+GPIO target writes received bytes through an unchecked/unallocated packet buffer
  • #111119 - drivers: spi: dw: spi_dw_configure() uses config->frequency as a divisor without validating it
  • #111238 - net: http: server: spurious zsock_poll() return of 0 leaks sockets and corrupts the kernel timeout list
  • #111277 - Neighbor solicitation header hop limit issue when CONFIG_NET_IPV6_ROUTE_MCAST is enabled
  • #111345 - net: http_server: static filesystem handler serves files outside the web root for paths containing ".."
  • #111407 - kernel: userspace: thread_idx_alloc() races on SMP and can hand out duplicate thread indices
  • #111411 - ESP32-S3 + Octal PSRAM: runtime flash erase/write fails with ESP_ERR_NOT_FOUND (261) — esp_flash driver chip initialized before PSRAM re-tunes MSPI
  • #111412 - drivers: i2c: i2c_dw: target stays stuck in CMD_SEND, write_requested() stops firing
  • #111416 - logging: z_vrfy_log_filter_set() accepts a negative src_id and indexes outside log_dynamic
  • #111420 - debug: coredump/shell: out-of-bounds read printing a stored coredump's target
  • #111427 - bluetooth: host: gatt_write_ccc_rsp() uses subscription params after releasing them
  • #111431 - net: ip: forwarded packets keep their original TTL / hop-limit (no decrement on the routing path)
  • #111447 - tests: arch: arm: Exclude custom IRQ controllers from IRQ test
  • #111481 - drivers: display: display_ili9xxx.c: x/y resolution changes breaks sample
  • #111534 - Bluetooth: GATT: notify/indicate checks the declaration's permissions, not the value's, when passed a characteristic declaration
  • #111545 - hal_espressif Kconfig can cause build to crashes if ZEPHYR_HAL_ESPRESSIF_MODULE_DIR is undefined
  • #111564 - bluetooth: host: classic: l2cap_br: Fix conf req/rsp length validation
  • #111888 - drivers: pwm: mcux_sctimer: counter stranded when device resumes before first channel config
  • #111929 - net: bridge: Memory leak on broadcast, multicast or matching MAC in eth_bridge_input_process.
  • #111935 - flash: z_vrfy_flash_copy is missing proper set of K_SYSCALL_DRIVER_FLASH invocations
  • #111936 - fs: ext2: Avoid using 0 value inode and block per group in calculations
  • #112027 - Bluetooth: esp32c3: bonding with pairing keys on Zephyr 4.4.1 hangs
  • #112204 - net: sockets: recvmsg() ancillary write checks total buffer, not room at the chosen slot
  • #112211 - Bluetooth: BAP: UC: NULL stream->group dereference on QoS Configured notification
  • #112235 - az3166_iotdevkit: Button B never gets released
  • #112315 - fs: ext2: Lack of validation of s_block_count, read from superblock, permitted block bitmap to be larger than ext2 block size
  • #112325 - Out-of-bounds read in PTP receive path: unchecked 4-bit message type indexes
  • #112421 - net: dhcp: name-lookup bounds checks use sizeof() instead of ARRAY_SIZE()
  • #112424 - net: ocpp: RPC-frame field parsing reads past fixed buffers on long/unterminated input
  • #112427 - mgmt: hawkbit: 1-byte heap overrun when NUL-terminating the response buffer
  • #112430 - Bluetooth: Host: bt_att_sent dereferences a freed channel after disconnect mid-transfer
  • #112432 - drivers: flash: sf32lb_mpi_qspi_nor: read/write offset check wraps on a negative offset
  • #112435 - kernel: k_queue_peek_head()/k_queue_peek_tail() dereference a node without holding the queue lock
  • #112441 - mgmt: updatehub: socket leak, NULL deref, and concurrency bugs in the OTA client
  • #112555 - drivers: bluetooth: hci_bflb / hci_bee: send() consumes the buffer on error paths
  • #112559 - usb: device_next: dfu: handle_download() dereferences buf without a NULL check
  • #112609 - drivers: usb: udc: MAX32 USB driver problem about nodata setup messages
  • #112613 - usb: device_next: CDC NCM to-host control handler ignores wLength when building responses
  • #112616 - net: sockets: userspace sendmsg/recvmsg verifiers re-read live user msghdr after copying it
  • #112621 - llext: ELF loader indexes arrays and sizes a stack VLA from unvalidated module header fields
  • #112782 - mgmt/settings: heap buffers leaked on access-hook and OOM paths in settings read/write/delete
  • #112838 - Bluetooth: Host: GATT: parse_read_std_char_desc() loops forever when a Read By Type Response has len 0
  • #112852 - logging: z_vrfy_z_log_msg_static_create() does not validate its arguments
  • #112931 - serial: pl011: error interrupts are never acknowledged and stay latched
  • #113039 - drivers: modem: hl7800 and wncm14a2a AT-response handlers write past fixed stack buffers
  • #113043 - net: 6lo: get_ihpc_inlined_size() reads past da_inline_size_table for reserved destination modes
  • #113048 - net: ipv6: handle_ra_6co() underflows memset length for context_len > 128
  • #113159 - LVGL Dynamic allocation doesn't work
  • #113265 - Bluetooth: Host: AoD 2US CTE type not validated in valid_conn_cte_tx_params()
  • #113266 - kernel: thread: thread_obj_validate() fails to oops a denied k_thread_join/k_thread_abort
  • #113299 - net: route: net_route_packet_if() forwards packets without decrementing the hop limit
  • #113303 - wifi: airoc: TX net_buf is leaked when whd_network_send_ethernet_data() fails
  • #113307 - mbox: userspace: z_vrfy_mbox_send validates msg->data then forwards the mutable userspace pointer
  • #113324 - fs: ext2: mount does not validate superblock s_log_block_size
  • #113328 - net: ocpp: server-message parsers mishandle malformed and oversized fields
  • #113339 - midi2: UMP Stream notification replies transmit uninitialised stack bytes
  • #113343 - drivers: virtio: device-supplied ring id and PCI cap_len used without bounds checking
  • #113346 - bluetooth: audio: has: notification work runs with NULL attributes when a bonded peer reconnects before bt_h...
Read more

Zephyr v4.3.1

Choose a tag to compare

@github-actions github-actions released this 23 Jun 12:27
v4.3.1

This is a maintenance release with fixes.

Issues Fixed

These GitHub issues were addressed since the previous 4.3.0 tagged release:

  • #55186 - posix: fnmatch: fix known bugs
  • #61464 - USB device stack (new and old) assertion on STM32
  • #95359 - spi_loopback fails on frdm_rw612 with DMA and/or cs_loopback
  • #96699 - drivers: spi: nrf_spim: Unused function warning when CONFIG_DEVICE_DEINIT_SUPPORT is disabled
  • #96762 - drivers: serial: uart_nrfx_uarte: Unused function warning when CONFIG_DEVICE_DEINIT_SUPPORT is disabled
  • #98491 - riscv: userspace: undefined symbol: z_stack_space_get
  • #98501 - pm: device_runtime: Issues with set/clear PD_CLAIMED flag in ISR_SAFE context
  • #98523 - ring_buffer: ring_buf_init may trigger assertion depending on Kconfig
  • #98588 - drivers: i2c: dw_i2c: i2c read time out on certain type of DW_I2C
  • #98768 - STM32F303 bxCAN: Last 2 bytes corrupted on TX pin, but registers are correct
  • #98782 - esp32c6: esp32h2: OpenThread issue
  • #98797 - boards: nxp: mimxrt1180_evk: J-Link script file not used when debugging
  • #99099 - STM32 QSPI sample shifting prevents communication with GD25Q128E flash chip
  • #99453 - sensor: current-amp: zero-current-offset no longer works
  • #99490 - MAX32650 SoC system clock configuration problem
  • #99491 - hwinfo: hwinfo test fails for MAX32657EVKIT board
  • #99535 - Issue with STM32 Ethernet and KSZ8081 Phy
  • #99563 - RP2350 Hazard3 doesn't default to XIP
  • #99588 - Bluetooth: Controller: nRF54Lx Radio Tx Power incorrect
  • #99644 - Siwx91x Compilation error with PM
  • #99659 - OpenThread Border Router issues in 4.3.0 release
  • #99682 - net: lib: dns: Unpacking query name can overflow the destination buffer
  • #99762 - mcumgr: Image management incorrectly identifies active slot when slots are on different flash devices
  • #99792 - HTTP Server Shows Error Log Message when iface goes down
  • #99795 - Telnet Shell Server Shows Error Log Message when iface goes down
  • #99797 - MCUmgr: OS: DateTime: Millisecond parsing erroneous
  • #99822 - stm32 EXTI driver: add support for STM32N6
  • #99895 - npcx9m6f_evb and frdm_k64f: kernel.common.stack_protection_arm_fpu_sharing fails
  • #99901 - drivers: entropy: gecko_trng: Error when getting entropy too soon after init
  • #99904 - soc: silabs: siwx91x: irq prio misalignment with hal
  • #99948 - drivers: ice40_fpga: k_usleep while holding a spinlock
  • #100040 - timer: cortex_m_systick: Compilation error if CONFIG_TIMER_READS_ITS_FREQUENCY_AT_RUNTIME is defined
  • #100211 - soc: silabs: siwx91x: ADC driver returns constant 0 mV
  • #100212 - No event code filterint for LVGL pointer process
  • #100225 - bluetooth: bt_conn reference leak in Frame Space Update in Zephyr 4.3.0
  • #100296 - west packages pip --install fails with permission error
  • #100715 - mgmt: mcumgr: firmware loader allows for self erasure
  • #100754 - bt test commands not working/crashing for nRF54LM20A DK board
  • #100903 - drivers: flash: stm32 ospi: detected erase type is always resetted
  • #101048 - drivers: xen: Uninitialized variable warning
  • #101151 - drivers: serial: NXP uart_mcux_flexcomm: instance interrupt config not saved during PM_DEVICE_ACTION_TURN_OFF
  • #101236 - NXP: Failed to disable random-mac-address in ethernet driver.
  • #101401 - logging: thread starvation for lower-priority producers
  • #101414 - ZVFS_OPEN_SIZE define applied irrespective of configuration
  • #101416 - It seems TCP accept had some issue during link changes
  • #102129 - Flash incorrectly tested on MAX32657 NS due to storage_partition
  • #102635 - gpio: mcux: Potential infinite interrupt hang when configuring
  • #102995 - OpenThread: build fails with CONFIG_OPENTHREAD_MTD enabled
  • #103029 - NVS startup fails after power loss during final ATE write
  • #103140 - TCAN4x5x initialization stalls with latest driver changes
  • #103239 - Race condition on usart/eusart silabs driver
  • #103242 - Watchdog timer on Siwx91x devices is not on pause during deep sleep
  • #103329 - Shared Flash access might be corrupted on SiWx91x SoC
  • #103339 - PM on SiWG91x SoC is broken
  • #103365 - MAX32655 UART fails to send some bytes on Zephyr 4.3
  • #103962 - RTIO: SQE flags not zeroed by some functions
  • #104208 - IPv4/6 fragmentation memory leak
  • #104248 - DNS query packet length check
  • #104253 - driver: clock_control: RCC_BDCR_LSEDRV_Pos undefined using STM32L0
  • #104652 - net: socketcan: length not always verified
  • #104748 - mcumgr: error codes of group "stat" incorrect
  • #104948 - net: lib: socket: tls: Potential out-of-bounds write in socket_op_vtable.connect
  • #105038 - net: lib: sockets: tls: Improve socket address storage
  • #105106 - arc: mpu: MPUv6 buffer validation race condition causes spurious access denials
  • #105216 - drivers: timer: stm32_lptim: fix incorrect configuration and harden against wrong usage
  • #105374 - drivers: gpio: sam: callback called when interrupt disabled
  • #105644 - SNTP uncertainty option invalids sntp_query
  • #105754 - net: sockets: msg->msg_iovlen is not validated in zsock_recvmsg sys call
  • #106109 - wifi: wifi_credentials: Static credentials are not validated
  • #106291 - Build fails when CONFIG_OPENTHREAD_CONFIG_DIAG_ENABLE is enabled.
  • #106334 - Thread-safety race condition in net_buf_unref
  • #106776 - net: tcp: Non-blocking connect failure leaks SYN retransmissions
  • #106894 - update Mbed TLS to 3.6.6
  • #106991 - net: tcp: use-after-free in net_tcp_foreach causes bus fault
  • #107081 - McuMgr fs_mgmt_file_upload handler does not check partial writes to filesystem
  • #107096 - cc3220sf_launchxl/cc3220sf missing ZVFS selection in sample
  • #107900 - net: ipv6: Neighbor Discovery packets validation is incorrect
  • #107920 - net: icmp: assert triggered sending icmp echo response with CONFIG_NET_STATISTICS
  • #107928 - net: lib: http_server: fix in websocket
  • https...
Read more

Zephyr v4.3.1-rc1

Zephyr v4.3.1-rc1 Pre-release
Pre-release

Choose a tag to compare

@cfriedt cfriedt released this 13 Jun 07:08
v4.3.1-rc1

Issues fixed

These GitHub issues were addressed since the previous 4.3.0 tagged release:

  • #55186 - posix: fnmatch: fix known bugs
  • #61464 - USB device stack (new and old) assertion on STM32
  • #95359 - spi_loopback fails on frdm_rw612 with DMA and/or cs_loopback
  • #96699 - drivers: spi: nrf_spim: Unused function warning when driver deinit Kconfig is disabled
  • #96762 - drivers: serial: uart_nrfx_uarte: Unused function warning when driver deinit Kconfig is disabled
  • #98491 - riscv: userspace: undefined symbol: z_stack_space_get
  • #98501 - pm: device_runtime: Issues with set/clear PD_CLAIMED flag in ISR_SAFE context
  • #98523 - ring_buffer: ring_buf_init may trigger assertion depending on Kconfig
  • #98588 - drivers: i2c: dw_i2c: i2c read time out on certain type of DW_I2C
  • #98768 - STM32F303 bxCAN: Last 2 bytes corrupted on TX pin, but registers are correct
  • #98782 - esp32c6: esp32h2: Openthread issue
  • #98797 - boards: nxp: mimxrt1180_evk: Jlink script file not used when debugging
  • #99099 - STM32 QSPI sample shifting prevents communication with GD25Q128E flash chip
  • #99453 - sensor: current-amp: zero-current-offset no longer works
  • #99490 - MAX32650 SoC system clock configuration problem
  • #99491 - hwinfo: hwinfo test fails for MAX32657EVKIT board
  • #99535 - 4.3.0 : Issue with STM32 Ethernet and KSZ8081 Phy
  • #99563 - RP2350 Hazard3 doesnt default to XIP
  • #99588 - Bluetooth: Controller: nRF54Lx Radio Tx Power incorrect
  • #99644 - Siwx91x Compilation error with PM
  • #99659 - OpenThread Border Router issues in 4.3 release
  • #99682 - net: lib: dns: Unpacking query name can overflow the destination buffer
  • #99762 - mcumgr: Image management incorrectly identifies active slot when slots are on different flash devices
  • #99792 - HTTP Server Shows Error Log Message when iface goes down
  • #99795 - Telnet Shell Server Shows Error Log Message when iface goes down
  • #99797 - MCUmgr: OS: DateTime: Millisecond parsing erroneous
  • #99822 - stm32 EXTI driver: add support for STM32N6
  • #99895 - npcx9m6f_evb and frdm_k64f: kernel.common.stack_protection_arm_fpu_sharing fails
  • #99901 - drivers: entropy: gecko_trng: Error when getting entropy too soon after init
  • #99904 - soc: silabs: siwx91x: irq prio misalignment with hal
  • #99948 - drivers: ice40_fpga: k_usleep while holding a spinlock
  • #100040 - timer: cortex_m_systick: Compilation error if CONFIG_TIMER_READS_ITS_FREQUENCY_AT_RUNTIME is defined
  • #100211 - soc: silabs: siwx91x: ADC driver returns constant 0 mV
  • #100212 - No event code filterint for LVGL pointer process
  • #100225 - bluetooth: bt_conn reference leak in Frame Space Update in Zephyr 4.3.0
  • #100296 - west packages pip --install fails with permission error
  • #100715 - mgmt: mcumgr: firmware loader allows for self erasure
  • #100754 - bt test commands not working/crashing for nRF54LM20A DK board
  • #100903 - drivers: flash: stm32 ospi: detected erase type is always resetted
  • #101048 - drivers: xen: Uninitialized variable warning
  • #101151 - drivers: serial: NXP uart_mcux_flexcomm: instance interrupt config not saved during PM_DEVICE_ACTION_TURN_OFF
  • #101236 - NXP: Failed to disable random-mac-address in ethernet driver.
  • #101401 - logging: thread starvation for lower-priority producers
  • #101414 - ZVFS_OPEN_SIZE define applied irrespective of configuration
  • #101416 - It seems tcp accept had some issue during link changes
  • #102129 - Flash incorrectly tested on MAX32657 NS due to storage_partition
  • #102635 - gpio: mcux: Potential infinite interrupt hang when configuring
  • #102995 - OpenThread: build fails with CONFIG_OPENTHREAD_MTD enabled
  • #103029 - NVS startup fails after power loss during final ATE write
  • #103140 - TCAN4x5x initialization stalls with latest driver changes
  • #103239 - Race condition on usart/eusart silabs driver
  • #103242 - Watchdog timer on Siwx91x devices is not on pause during deep sleep
  • #103329 - Shared Flash access might be corrupted on SiWx91x SoC
  • #103339 - PM on SiWG91x SoC is broken
  • #103365 - MAX32655 UART fails to send some bytes on Zephyr 4.3
  • #103962 - RTIO: SQE flags not zeroed by some functions
  • #104208 - IPv4/6 fragmentation memory leak
  • #104248 - DNS query packet length check
  • #104253 - driver: clock_control: RCC_BDCR_LSEDRV_Pos undefined using STM32L0
  • #104652 - net: socketcan: length not always verified
  • #104748 - [mcumgr] error codes of group "stat" incorrect
  • #104948 - net: lib: socket: tls: Potential out-of-bounds write in socket_op_vtable::connect
  • #105038 - net: lib: sockets: tls: Improve socket address storage
  • #105106 - arc: mpu: MPUv6 buffer validation race condition causes spurious access denials
  • #105216 - drivers: timer: stm32_lptim: fix incorrect configuration and harden against wrong usage
  • #105374 - drivers: gpio: sam: callback called when interrupt disabled
  • #105644 - SNTP uncertainty option invalids sntp_query()
  • #105754 - net: sockets: msg->msg_iovlen is not validated in zsock_recvmsg() sys call
  • #106109 - wifi: wifi_credentials: Static credentials are not validated
  • #106291 - Build fails when OPENTHREAD_CONFIG_DIAG_ENABLE is enabled.
  • #106334 - Thread-safety race condition in net_buf_unref
  • #106776 - net: tcp: Non-blocking connect failure leaks SYN retransmissions
  • #106894 - update Mbed TLS to 3.6.6
  • #106991 - net: tcp: use-after-free in net_tcp_foreach() causes bus fault
  • #107081 - McuMgr fs_mgmt_file_upload handler does not check partial writes to filesystem
  • #107096 - cc3220sf_launchxl/cc3220sf missing ZVFS selection in sample
  • #107900 - net: ipv6: Neighbor Discovery packets validation is incorrect
  • #107920 - net: icmp: assert triggered sending icmp echo response with CONFIG_NET_STATISTICS=y
  • #107928 - net: lib: http_server: Fix in websocket must be back ported to 3.7 and 4.3
  • #108004 - drivers: entropy: stm32: bad locking sequence
  • #108149 - Renaming configuration file in WiFi Shell sample causes errors when building the associated board documentation in branch v4.3-branch
  • #108559 - IP address parsing issue
  • #108637 - tests/drivers/bbram/generic/ fails at random due to drivers/bbram/bbram_microchip_mcp7940n_emul.c
  • #108835 - adin2111: Communication gets stuck after high bandwidth transfer
  • #108846 - Validate DNS rdata length in dns_unpack_answer
  • #108848 - wifi: nrf70: Missing bounds check on TWT event buffer
  • #108963 - net: lwm2m: URI string may be unterminated in FW pull mode
  • #109053 - native_sim: FUSE files are opened write-only
  • #109063 - The issue in Bluetooth Mesh solicitation PDU parsing
  • #109128 - fs: backend file resource leak when fs_open with FS_O_TRUNC fails during truncate
  • #109133 - Undefined bitwise shift behavior in PTP port management interval handling
  • #109257 - xtensa: mpu: fix arch_buffer_validate() if overflow
  • #109549 - Security advisory GHSA-4vqm-pw24-g9jp / CVE 2026-5590 fix not available for Zephyr 4.3
  • #109620 - Bluetooth: Controller: Fix OOB read in ISOAL
  • #109857 - posix: mqueue: fix integer overflow in mq_open() buffer allocation
  • #110032 - fs: ext2: validate directory entry structure before traversal #108226
  • #110077 - k_pipe_read in ISR causing fault
  • #110303 - Bluetooth: Mesh: PrivateBeaconKey PSA key leak after subnet deletion
  • #110393 - bluetooth: l2cap: validate alloc_buf user data
  • #110645 - net: sockets: recvmsg() ancillary-data capacity check undercounts cmsg size
  • #110651 - usb: device_next: cdc_ncm: TX thread deadlocks when usbd_ep_enqueue() fails
  • #110762 - bluetooth: classic: hfp_hf: cind_handle_values() writes past ind_table on a long +CIND list
  • #110766 - drivers: serial: pl011: TX enable spins forever when CTS flow control blocks transmission
  • #110771 - net: sockets: getaddrinfo() retry after a DNS timeout leaves the previous query in flight and touches stale stack state
  • #110775 - Bluetooth: BAP: unicast client dereferences NULL stream->qos when a QoS Configured notification arrives before the stream is added to a group
  • #110857 - net: sntp: close-while-polling use-after-free in sntp_close_async
  • #110866 - net: dns: .local suffix check reads past the end of the hostname string
  • #110915 - pb-adv bearer resets the protocol timer unconditionally
  • #110956 - Bluetooth: ISO: bt_iso_recv() pulls the SDU header without checking buf->len
  • #110967 - Bluetooth: BAP: Broadcast Assistant shares one att_buf across all connections
  • #111016 - kernel: userspace: dynamic kernel-object list freed under a different lock than it is traversed

Zephyr v4.4.1

Choose a tag to compare

@MaureenHelm MaureenHelm released this 10 Jun 18:06
v4.4.1

This is a bugfix release for Zephyr 4.4.0.

Security Vulnerability Related

More detailed information can be found in:
https://docs.zephyrproject.org/latest/security/vulnerabilities.html

Issues fixed

The following issues are addressed by this release:

  • #99054 - ARM64: Wrong register is being saved in coredump, causing corrupted backtrace show in gdb
  • #100542 - soc/espressif/esp32s3: undefined reference to 'log_const_soc' when CONFIG_PM=y
  • #104000 - display_check: ASSERTION FAIL / kernel panic in test_display_by_capture on mimxrt700_evk (mimxrt798s/cm33_cpu0, co5300@0)
  • #104480 - samples/subsys/usb/console hangs when opened with picocom on blackpill_f411ce (STM32F411, Zephyr 4.3.99)
  • #104900 - Bluetooth LE host qualification for 4.4 release
  • #105265 - menuconfig fails on Windows when using multiple shields
  • #105317 - mcumgr: os grp: mpstat incorrect cbor layout
  • #105521 - Drivers: display: ili9xxx driver color order problem
  • #106150 - net: all NXP platform dhcp_client does not work
  • #106580 - spi mchp g1 driver configuration issues
  • #106850 - sensor ism6hg256x returns wrong values via the shell
  • #106872 - ethernet: dwmac: no multicast packets are received
  • #106906 - Fix CSI data overflow issue
  • #106971 - hardfault on boot with samples/hello_world for old flash dts layout NXP platforms
  • #106984 - Regression in net/ethernet.h: C++ build failure (invalid cast from const void *)
  • #106991 - net: tcp: use-after-free in net_tcp_foreach() causes bus fault
  • #107061 - settings: runtime: settings_runtime_set crashes when h_set is NULL
  • #107067 - Sensor:Driver:ST: lsm6dsvxxxx - IRQ pin goes high before GPIO IRQ is set
  • #107081 - McuMgr fs_mgmt_file_upload handler does not check partial writes to filesystem
  • #107105 - Sensor:Driver:ST: lsm6dsvxxxx - setting the SFLP changes the ODR for mag and accel
  • #107201 - drivers: ethernet: esp32: DMA buffer processing skips some buffers if multiple ready
  • #107302 - Secure Storage not enabling PSA_CRYPTO
  • #107355 - stm32: H7RS: backup access for reading some RTC registers
  • #107388 - mcxw7x ieee driver / OT samples: DUT can not attach to network when SED/SSED
  • #107398 - OpenThread Border Router cannot forward inbound multicast packets on ethernet
  • #107412 - mcause: 2, Illegal instruction on ESP32-C3 when using localtime_r with tzset()
  • #107422 - ESP32S3 PSRAM is not working properly: only work in octal+40M
  • #107442 - samples/drivers/adc/adc_dt prints garbage data on ADCs with <= 16-bit buffer
  • #107540 - esp32c5_devkitc psram size
  • #107585 - soc: st: stm32h7x: NUM_IRQS computed too small since Zephyr 4.4, causing build failure
  • #107589 - net: dns: Forward all DNS packets if callback is installed still not functional
  • #107594 - mgmt: mcumgr: grp: img_mgmt: Non-progressive erase in swap using offset mode erases out of bounds
  • #107621 - Flashing MAX32 devices with OpenOCD picks first connected device and ignores --serial option
  • #107627 - STM32 F4 with external USB PHY fails to build
  • #107632 - MAX32 SPI driver race condition leads to timed out transceive transactions
  • #107675 - stm32: nucleo-wba65ri 'ns' variant fails to boot
  • #107773 - Stepper: adi_tmc: Build fails with unresolved function read_actual_position()
  • #107809 - BusFault in mcumgr_serial_process_frag() when net_buf allocation fails
  • #107814 - samples: net: HTTP server configuration is broken
  • #107900 - net: ipv6: Neighbor Discovery packets validation is incorrect
  • #107908 - Fix missing ESP32-C5 uart test coverage
  • #107920 - net: icmp: assert triggered sending icmp echo response with CONFIG_NET_STATISTICS=y
  • #107938 - drivers: sdhc: sam_hsmci: Initialize variables
  • #108004 - drivers: entropy: stm32: bad locking sequence
  • #108035 - STM32WBAx : Thread GRL tests failure due to 15.4 driver issue
  • #108258 - mapped-partition linker fails with non-XIP boot
  • #108267 - STM32 TF-M regression.sh script corrupted after 'west flash'
  • #108285 - PM issues regarding STM32WB09 in Zephyr v4.4.0
  • #108391 - flash_shell does not consider erase command size argument
  • #108466 - net: sockets: tls: addr may be used uninitialized
  • #108559 - IP address parsing issue
  • #108631 - tests/lib/devicetree/api_ext fails to build for some targets
  • #108633 - IRK is not sent to controller when extended advertisement enabled but started via bt_le_adv_start
  • #108636 - tests/subsys/zbus/proxy_agent/ipc_backend fails for nrf5340bsim//cpunet
  • #108680 - drivers.flash.common.test_storage_partition fails for nrf54l15bsim/nrf54l15/cpuapp
  • #108681 - Broken link in release note of Zephyr 4.4
  • #108737 - Update MCUboot to v2.4.0 release
  • #108785 - Bluetooth: ESP32-S3 + iOS: HCI 0x3D MIC failure on every reconnect after LE SC pair
  • #108835 - adin2111: Communication gets stuck after high bandwidth transfer
  • #108846 - Validate DNS rdata length in dns_unpack_answer
  • #108848 - wifi: nrf70: Missing bounds check on TWT event buffer
  • #108915 - modem: cmux: user pipe flow control stuck
  • #108963 - net: lwm2m: URI string may be unterminated in FW pull mode
  • #109053 - native_sim: FUSE files are opened write-only
  • #109188 - drivers: ethernet: esp32: unused driver static function when ref_clk_output_gpios is not used
  • #109257 - xtensa: mpu: fix arch_buffer_validate() if overflow
  • #109325 - soc: esp32: abort() while using sleep-hold-en flag
  • #109497 - OpenThread Border Router - Incorrect computation of IPV6 packet checksum
  • #109515 - MAX32 USB support broken for some transfer types on Zephyr 4.4
  • #109577 - esp32: gpio: gpio overflow due to BIT operation
  • #109620 - Bluetooth: Controller: Fix OOB read in ISOAL
  • #109625 - net: sockets/tls: validate buffer in peer_connection_id_value_get
  • #109652 - drivers: mcux_flexcomm: missing init_common() on PM_DEVICE_ACTION_RESUME and SUSPEND for I2C, UART, I2S, SPI
  • #109759 - drivers: can: mcux: flexcan: Fix off-by-one error in MB IRQ handling
  • #109848 - Usage fault due to unaligned access in BLE Mesh on MCXW23
  • #109857 - posix: mqueue: fix integer overflow in mq_open() buffer allocation
  • #109860 - ESP32 PSRAM may abort() when cache invalidate is called
  • #109869 - Espressif's esptool may fail depending on elf segment alignment
  • #109899 - STM32 ADC differential channel issue
  • #110019 - pm: esp32: GPIO_INT_WAKEUP flag usage with CONFIG_INPUT
  • #110032 - fs: ext2: validate directory entry structure before traversal #108226
  • #110079 - Backport 108049 [arm64: Fix clang unused warnings in mmu.c] to v4.4-branch

Zephyr v4.4.1-rc1

Zephyr v4.4.1-rc1 Pre-release
Pre-release

Choose a tag to compare

@MaureenHelm MaureenHelm released this 03 Jun 21:23
v4.4.1-rc1

Issues fixed

These GitHub issues were addressed since the previous 4.4.0 tagged release:

  • #99054 - ARM64: Wrong register is being saved in coredump, causing corrupted backtrace show in gdb
  • #100542 - soc/espressif/esp32s3: undefined reference to 'log_const_soc' when CONFIG_PM=y
  • #104000 - display_check: ASSERTION FAIL / kernel panic in test_display_by_capture on mimxrt700_evk (mimxrt798s/cm33_cpu0, co5300@0)
  • #104480 - samples/subsys/usb/console hangs when opened with picocom on blackpill_f411ce (STM32F411, Zephyr 4.3.99)
  • #104900 - Bluetooth LE host qualification for 4.4 release
  • #105265 - menuconfig fails on Windows when using multiple shields
  • #105317 - mcumgr: os grp: mpstat incorrect cbor layout
  • #105521 - Drivers: display: ili9xxx driver color order problem
  • #106150 - net: all NXP platform dhcp_client does not work
  • #106580 - spi mchp g1 driver configuration issues
  • #106850 - sensor ism6hg256x returns wrong values via the shell
  • #106872 - ethernet: dwmac: no multicast packets are received
  • #106906 - Fix CSI data overflow issue
  • #106971 - hardfault on boot with samples/hello_world for old flash dts layout NXP platforms
  • #106984 - Regression in net/ethernet.h: C++ build failure (invalid cast from const void *)
  • #106991 - net: tcp: use-after-free in net_tcp_foreach() causes bus fault
  • #107061 - settings: runtime: settings_runtime_set crashes when h_set is NULL
  • #107067 - Sensor:Driver:ST: lsm6dsvxxxx - IRQ pin goes high before GPIO IRQ is set
  • #107081 - McuMgr fs_mgmt_file_upload handler does not check partial writes to filesystem
  • #107105 - Sensor:Driver:ST: lsm6dsvxxxx - setting the SFLP changes the ODR for mag and accel
  • #107201 - drivers: ethernet: esp32: DMA buffer processing skips some buffers if multiple ready
  • #107302 - Secure Storage not enabling PSA_CRYPTO
  • #107355 - stm32: H7RS: backup access for reading some RTC registers
  • #107388 - mcxw7x ieee driver / OT samples: DUT can not attach to network when SED/SSED
  • #107398 - OpenThread Border Router cannot forward inbound multicast packets on ethernet
  • #107412 - mcause: 2, Illegal instruction on ESP32-C3 when using localtime_r with tzset()
  • #107422 - ESP32S3 PSRAM is not working properly: only work in octal+40M
  • #107442 - samples/drivers/adc/adc_dt prints garbage data on ADCs with <= 16-bit buffer
  • #107540 - esp32c5_devkitc psram size
  • #107585 - soc: st: stm32h7x: NUM_IRQS computed too small since Zephyr 4.4, causing build failure
  • #107589 - net: dns: Forward all DNS packets if callback is installed still not functional
  • #107594 - mgmt: mcumgr: grp: img_mgmt: Non-progressive erase in swap using offset mode erases out of bounds
  • #107621 - Flashing MAX32 devices with OpenOCD picks first connected device and ignores --serial option
  • #107627 - STM32 F4 with external USB PHY fails to build
  • #107632 - MAX32 SPI driver race condition leads to timed out transceive transactions
  • #107675 - stm32: nucleo-wba65ri 'ns' variant fails to boot
  • #107773 - Stepper: adi_tmc: Build fails with unresolved function read_actual_position()
  • #107809 - BusFault in mcumgr_serial_process_frag() when net_buf allocation fails
  • #107814 - samples: net: HTTP server configuration is broken
  • #107900 - net: ipv6: Neighbor Discovery packets validation is incorrect
  • #107908 - Fix missing ESP32-C5 uart test coverage
  • #107920 - net: icmp: assert triggered sending icmp echo response with CONFIG_NET_STATISTICS=y
  • #107938 - [backport]: drivers: sdhc: sam_hsmci: Initialize variables
  • #108004 - drivers: entropy: stm32: bad locking sequence
  • #108035 - STM32WBAx : Thread GRL tests failure due to 15.4 driver issue
  • #108258 - mapped-partition linker fails with non-XIP boot
  • #108267 - STM32 TF-M regression.sh script corrupted after 'west flash'
  • #108285 - PM issues regarding STM32WB09 in Zephyr v4.4.0
  • #108391 - flash_shell does not consider erase command size argument
  • #108466 - [v4.4] net: sockets: tls: addr may be used uninitialized
  • #108559 - IP address parsing issue
  • #108631 - tests/lib/devicetree/api_ext fails to build for some targets
  • #108633 - IRK is not sent to controller when extended advertisement enabled but started via bt_le_adv_start
  • #108636 - tests/subsys/zbus/proxy_agent/ipc_backend fails for nrf5340bsim//cpunet
  • #108680 - drivers.flash.common.test_storage_partition fails for nrf54l15bsim/nrf54l15/cpuapp
  • #108681 - Broken link in release note of Zephyr 4.4
  • #108737 - [v4.4-branch] Update MCUboot to v2.4.0 release
  • #108785 - Bluetooth: ESP32-S3 + iOS: HCI 0x3D MIC failure on every reconnect after LE SC pair
  • #108835 - adin2111: Communication gets stuck after high bandwidth transfer
  • #108846 - Validate DNS rdata length in dns_unpack_answer
  • #108848 - wifi: nrf70: Missing bounds check on TWT event buffer
  • #108915 - modem: cmux: user pipe flow control stuck
  • #108963 - net: lwm2m: URI string may be unterminated in FW pull mode
  • #109053 - native_sim: FUSE files are opened write-only
  • #109188 - drivers: ethernet: esp32: unused driver static function when ref_clk_output_gpios is not used
  • #109257 - [backport] xtensa: mpu: fix arch_buffer_validate() if overflow
  • #109325 - soc: esp32: abort() while using sleep-hold-en flag
  • #109497 - OpenThread Border Router - Incorrect computation of IPV6 packet checksum
  • #109515 - MAX32 USB support broken for some transfer types on Zephyr 4.4
  • #109516 - [Backport v4.4-branch] Failed to backport #108447
  • #109577 - esp32: gpio: gpio overflow due to BIT operation
  • #109620 - [backport] Bluetooth: Controller: Fix OOB read in ISOAL
  • #109625 - [backport] net: sockets/tls: validate buffer in peer_connection_id_value_get
  • #109652 - drivers: mcux_flexcomm: missing init_common() on PM_DEVICE_ACTION_RESUME and SUSPEND for I2C, UART, I2S, SPI
  • #109759 - drivers: can: mcux: flexcan: Fix off-by-one error in MB IRQ handling
  • #109848 - Usage fault due to unaligned access in BLE Mesh on MCXW23
  • #109857 - [backport] posix: mqueue: fix integer overflow in mq_open() buffer allocation
  • #109860 - ESP32 PSRAM may abort() when cache invalidate is called
  • #109869 - Espressif's esptool may fail depending on elf segment alignment
  • #109899 - v4.4: STM32 ADC differential channel issue
  • #110019 - pm: esp32: GPIO_INT_WAKEUP flag usage with CONFIG_INPUT
  • #110032 - [backport] fs: ext2: validate directory entry structure before traversal #108226
  • #110071 - [Backport v4.4-branch] Failed to backport #109304
  • #110079 - Backport 108049 [arm64: Fix clang unused warnings in mmu.c] to v4.4-branch
  • #110369 - Zephyr 4.4.1 Release
  • #110373 - [Backport v4.4-branch] Failed to backport #109651

Zephyr 4.4.0

Choose a tag to compare

@github-actions github-actions released this 14 Apr 21:33
v4.4.0

We are pleased to announce the release of Zephyr 4.4.0!

For a closer look at some of the key additions in this release, check out the announcement article on the Zephyr blog, along with its companion video.

Major enhancements with this release include:

OpenRISC support

Zephyr now supports the OpenRISC architecture.

Toolchain updates: Zephyr SDK 1.0 and C17

Zephyr 4.4 is the first release to support Zephyr SDK 1.0, with an upgraded GNU toolchain, experimental Clang/LLVM support, and multi-platform QEMU and OpenOCD host tools.

Zephyr now defaults to C17 as its minimum required C standard version.

Networking enhancements

The Wi-Fi management stack now supports Wi-Fi P2P (Wi-Fi Direct), allowing devices to discover and connect directly without a traditional access point.

The networking stack also adds support for WireGuard VPN, enabling secure, low-overhead tunneling.

USB host

Experimental USB host support has been significantly expanded with a new host-class driver framework and support for UVC cameras on Zephyr devices acting as USB hosts.

New driver classes

Zephyr 4.4 adds several new driver APIs, including:

Zbus async listeners and proxy agents

Zbus async listeners enable non-blocking observer callbacks via workqueues.

Zbus proxy agents extend publish-subscribe messaging across CPU and domain boundaries over IPC.

Pressure-based CPU frequency scaling

The experimental CPU frequency scaling subsystem now includes a pressure-based policy that adjusts CPU frequency according to scheduler load.

ARM Cortex-M context switching performance improvements

A new context switch implementation for ARM Cortex-M, enabled via CONFIG_USE_SWITCH, delivers significant performance improvements.

NAND flash support

A new Flash Translation Layer (FTL) disk driver (zephyr,ftl-dhara) provides wear leveling and bad block management and enables NAND flash memories to be utilized as standard disk devices.

Developer experience improvements

This release adds several new tools and improvements to development and testing workflows:

  • A new dashboard consolidates build information such as RAM and ROM footprint, Devicetree configuration, subsystem initialization levels, and more in a single report.
  • A new display driver for QEMU targets simplifies development of display-based applications in environments where the native simulator is unavailable.
  • A new heap hardening mechanism (CONFIG_SYS_HEAP_HARDENING) provides multiple levels of runtime protection against heap corruption.
  • New scope-based cleanup helpers provide RAII/defer-style automatic cleanup in C when leaving scope.
  • The new ztest benchmarking framework provides a standardized way to create cycle-accurate benchmarks, with automated data collection, overhead compensation, and statistical reporting.

Expanded board support

This release adds support for 121 new boards and 31 new shields.

Full Release Notes

The full release notes and list of major changes since the last release can be found here.

An overview of the changes required or recommended when migrating your application from Zephyr
v4.3.0 to Zephyr v4.4.0 can be found in the separate migration guide.

Release Lifecycle

The 4.4 release will be supported until April 12th, 2027.

Additional release information may be found on the Release Management Wiki.

Thanks 🙏

Many thanks to the 931 individuals who contributed to this release! 🚀

Maureen, Stephanos, and the Zephyr Release Team

Zephyr v4.4.0-rc3

Zephyr v4.4.0-rc3 Pre-release
Pre-release

Choose a tag to compare

@MaureenHelm MaureenHelm released this 08 Apr 20:33
v4.4.0-rc3

Hi Zephyr developers!

The third release candidate for Zephyr 4.4.0 has been tagged:
https://github.com/zephyrproject-rtos/zephyr/releases/tag/v4.4.0-rc3

The merge window for features and enhancements remains closed until 4.4.0 is released.

We continue in the stabilization phase, and only blocker bug-fixes and documentation patches may be merged to the main branch. As a reminder to maintainers, please send PRs to update the release notes and migration guide for any areas you manage.

You may continue to submit pull requests for new features to gather feedback early or collaborate with others, but the release team would like to encourage everyone to focus on testing, fixing any blocker bugs found, and finalizing release notes.

Other bugs which are not critical enough to be categorized as blocker, but should still be part of 4.4 should be marked with the backport v4.4-branch label so they can be considered for the first dot release.

Regards,
The Zephyr Release Team

Release milestone dates:
https://github.com/zephyrproject-rtos/zephyr/wiki/Release-Management

Release process:
https://docs.zephyrproject.org/latest/project/release_process.html

Blocker bugs process:
https://docs.zephyrproject.org/latest/project/release_process.html#blocker-bugs

Regards,
The release team.

Zephyr v4.4.0-rc2

Zephyr v4.4.0-rc2 Pre-release
Pre-release

Choose a tag to compare

@MaureenHelm MaureenHelm released this 02 Apr 21:06
v4.4.0-rc2

Hello Zephyr developers!

The second release candidate for Zephyr 4.4.0 has been tagged:

https://github.com/zephyrproject-rtos/zephyr/releases/tag/v4.4.0-rc2

We are still in the stabilization phase, and only bug-fix, documentation, and stabilization patches may be merged to the main branch. Matching bug reports for bugfix pull requests are recommended but not required.

You may continue to submit pull requests for new features to gather feedback early or collaborate with others, but the release team would like to encourage everyone to focus on testing, documentation improvements, and fixing bugs. Any feature pull requests should be tagged with the 4.5.0 release milestone.

We anticipate the coming weeks to be very busy reducing overall bug count. Please give this RC a test drive and report any issues on supported platforms (with a PR if possible).

Release milestone dates:
https://github.com/zephyrproject-rtos/zephyr/wiki/Release-Management

Release process:
https://docs.zephyrproject.org/latest/project/release_process.html

Regards,
The release team.