Ben Meadors 0739d2a68c fix(raspihttp): memory safety and error-path leaks in PiWebServer (#11451)
- handleAPIv1ToRadio: the toRadio handler memcpy'd a fixed 512 bytes
  out of the request body regardless of its actual size. ulfius
  allocates binary_body at exactly binary_body_length bytes and leaves
  it NULL for a body-less PUT, so short bodies caused a heap overread
  and empty ones dereferenced NULL. The unclamped length (ulfius
  accepts up to 1024) was also handed to handleToRadio, reading past
  the 512-byte stack buffer. Clamp both directions, matching the ESP32
  ContentHandler behavior.

- callback_static_file: the stream-free callback only runs when
  ulfius_set_stream_response succeeds, so the failure branch leaked the
  FILE (and its fd) on every failed request. Close it and return 500.

- CheckSSLandLoad: free cert_pem before the missing-key return; the
  constructor retries after regenerating certs and the reload
  overwrote (leaked) the first buffer.

- generate_rsa_key / CreateSSLCertificate: free the EVP_PKEY_CTX,
  EVP_PKEY, and X509 on their error returns; previously only the
  success paths released them.
2026-08-12 19:12:32 -05:00
2021-10-09 17:15:12 +11:00
2026-08-06 14:05:07 +00:00
2024-09-24 15:24:08 -05:00
2026-08-11 14:56:11 +02:00
2026-07-01 19:01:27 -05:00
2026-01-29 10:06:58 -06:00
2024-11-28 06:26:51 -06:00
2024-09-04 15:33:28 -07:00
2026-07-28 11:09:40 +00:00
2026-01-29 10:06:58 -06:00
2026-01-29 10:06:58 -06:00
2026-07-01 19:01:27 -05:00
2025-01-13 12:24:05 +08:00
2026-01-29 10:06:58 -06:00

Meshtastic Logo

Meshtastic Firmware

GitHub release downloads CI CLA assistant Fiscal Contributors Vercel

meshtastic%2Ffirmware | Trendshift

Overview

This repository contains the official device firmware for Meshtastic, an open-source LoRa mesh networking project designed for long-range, low-power communication without relying on internet or cellular infrastructure. The firmware supports various hardware platforms, including ESP32, nRF52, RP2040/RP2350, and Linux-based devices.

Meshtastic enables text messaging, location sharing, and telemetry over a decentralized mesh network, making it ideal for outdoor adventures, emergency preparedness, and remote operations.

Get Started

Join our community and help improve Meshtastic! 🚀

Stats

Alt

S
Description
No description provided
Readme GPL-3.0
72 MiB
0 Stars 1 Watchers 0 Forks
2026-09-01 21:05:50 +08:00
Languages
C++ 72.5%
C 23.7%
Python 2%
Shell 1.2%
Batchfile 0.2%
Other 0.2%