nRF Connect SDK v3.4.1 Release Notes

nRF Connect SDK delivers reference software and supporting libraries for developing low-power wireless applications with Nordic Semiconductor products in the nRF52, nRF53, nRF54, nRF70, and nRF91 Series. The SDK includes open source projects (TF-M, MCUboot, OpenThread, Matter, and the Zephyr RTOS), which are continuously integrated and redistributed with the SDK.

Release notes might refer to “experimental” support for features, which indicates that the feature is incomplete in functionality or verification, and can be expected to change in future releases. To learn more, see Software maturity levels.

Highlights

This patch release adds the following changes on top of the nRF Connect SDK v3.4.0:

  • The nRF Connect SDK v3.4.1 is based on Zephyr 4.4.2, Mbed TLS 4.1.1, and TF-M 2.3.1.

    This patch release is part of the v3.4 release branch, which has long-term support (LTS) for a period of five years. During this period, patch releases will provide updates for security vulnerabilities and critical bug fixes. These patch releases will not contain breaking changes unless security fixes require them.

  • The v3.4 release branch is the last nRF Connect SDK release branch that includes support for nRF52 Series devices. The nRF52 Series devices are considered feature complete, and support for them will be removed from samples and applications in the main branch.

Added the following supported features:

  • CAN:

    • Power management support has been added to the nRF CAN FD driver. The nRF54H20 SoC can now enter sleep mode when the CAN controller is enabled with CONFIG_CAN set to y but not started with can_start().

  • FMN:

    • The FMN extension has been updated to the FMN R3 specification. For details about the implementation and compliance, see the extension documentation.

  • SysCtrl WDT:

    • The SysCtrl WDT service has been added for the nRF54H20 SoC. It enables continuous low-power WDT operation.

Added the following experimental features:

  • Experimental support for the nRF54LC10A SoC.

Add-ons:

  • New HID add-on:

    • The nRF Desktop HID application will be moved to a dedicated HID add-on. Its existing feature set will be maintained in the nRF Connect SDK v3.4 LTS releases, but new features will be introduced only in the add-on.

Deprecated:

  • Deprecated features will not be removed from the LTS branch. It is recommended that all new designs using Nordic devices exclude deprecated features for active development and deployment.

Release tag

The release tag for the nRF Connect SDK manifest repository (https://github.com/nrfconnect/sdk-nrf) is v3.4.1. Check the west.yml file for the corresponding tags in the project repositories.

To use this release, check out the tag in the manifest repository and run west update. See Install the nRF Connect SDK code and toolchain and Updating the repositories for more information.

For information on the included repositories and revisions, see Repositories and revisions for v3.4.1.

IDE and tool support

nRF Connect extension for Visual Studio Code is the recommended IDE for nRF Connect SDK v3.4.1. See the Installation section for more information about supported operating systems and toolchain.

Supported modem firmware

See the following documentation for an overview of which modem firmware versions have been tested with this version of the nRF Connect SDK:

Use the latest version of the Programmer app of nRF Connect for Desktop to update the modem firmware. See Programming nRF91 Series DK firmware for instructions.

Known issues

Known issues are only tracked for the latest official release. See known issues for nRF Connect SDK v3.4.1 for the list of issues valid for the latest release.

Changelog

The following sections provide detailed lists of changes by component.

Bootloaders and DFU

  • Added:

    • The hidden CONFIG_NCS_MCUBOOT_ENCRYPTION_HMAC_SHA256 Kconfig option to select HMAC-SHA256 with X25519 for compatibility with existing projects that use it. The option is hidden and requires addition of a Kconfig override in your project. This is intentional as HMAC-SHA512 is recommended over HMAC-SHA256.

    • Support for the application core of the nRF54LS05A SoC to MCUboot and secure boot sysbuild, including the secure boot locking and immutable region handling features aligned with the nRF54LS05B SoC.

  • Fixed:

    • Sequential updates on the nRF5340 SoC. The address-based detection of the update candidate type allows placing the network core update candidate in the same partition used for the application update candidate. The build system no longer requires dedicated slots for the network core update candidate. You can enable software-based downgrade prevention for network core updates. MCUboot now erases the secondary slot after the network core is updated.

Developing with nRF54L Series

  • Added support for the nRF54LC10A SoC and the nrf54lc10dk board.

Protocols

This section provides detailed lists of changes by protocol. See Samples for lists of changes for the protocol-related samples.

Bluetooth Mesh

  • Fixed an issue where an LPN that terminated a friendship by sending a Friend Clear message with TTL set to 0 never received the Friend Clear Confirm message from the Friend node.

Matter

  • Replaced the tables on the RAM and flash memory requirements and Reference Matter memory layouts pages with memory layout charts.

Security

  • Updated:

    • Oberon PSA Crypto from v2.0.0 to v2.1.0. The new version has minor updates in internal APIs, restructures the directory hierarchy, and improves native support for built-in keys.

    • nrf_cc3xx_platform and nrf_cc3xx_mbedcrypto libraries to version v0.9.23. Improved PSA driver error reporting and fixed an issue that caused incorrect authentication tag generation in GCM when multiple calls to psa_aead_update_ad() were made.

Trusted Firmware-M (TF-M)

Mbed TLS

Applications

This section provides detailed lists of changes by application.

nRF Desktop

  • Future development of the nRF Desktop HID application reference design will move to a dedicated nRF Connect SDK Add-on (HID Add-on). Existing feature set will be maintained in the nRF Connect SDK 3.4 long-term support (LTS) releases, but new features will be introduced only in the Add-on. The add-on will support the nRF54L Series.

  • Added:

    • Support for the nrf54ls05dk/nrf54ls05a/cpuapp and nrf54lc10dk/nrf54lc10a/cpuapp board targets.

    • The release_fast_pair build type for the nrf54ls05dk/nrf54ls05a/cpuapp and nrf54ls05dk/nrf54ls05b/cpuapp board targets. The configuration acts as a HID mouse with Fast Pair support. It uses MCUboot in direct-xip mode with software-based image signature verification.

Samples

This section provides detailed lists of changes by sample.

Bluetooth samples

Bluetooth Mesh samples

Bluetooth Fast Pair samples

Cryptography samples

  • Added support for the nRF54LC10A SoC (with and without TF-M) in the crypto samples.

DFU samples

Enhanced ShockBurst samples

  • Added support for the nrf54lc10dk/nrf54lc10a/cpuapp, nrf54lc10dk/nrf54lc10a/cpuapp/ns, and nrf54ls05dk/nrf54ls05a/cpuapp board targets in all samples.

Matter samples

  • Added support for the nrf54lc10dk/nrf54lc10a/cpuapp board target for the following samples:

    • Matter template sample

    • Matter temperature sensor sample

    DFU is not supported on this board target, as the nRF54LC10 DK is not equipped with external flash. See External flash for more information.

  • Fixed an issue where the binding table was not printed correctly when the cluster ID was not set.

Trusted Firmware-M (TF-M) samples

  • Added support for the nRF54LC10A SoC in the TF-M samples.

Thread samples

  • Added experimental support for the nRF54LC10A SoC to all Thread samples.

Scripts

This section provides detailed lists of changes by script.

HID configurator

  • Future development of the HID configurator for nRF Desktop will move to a dedicated nRF Connect SDK add-on (HID Add-on). Existing feature set will be maintained in the nRF Connect SDK 3.4 long-term support (LTS) releases, but new features will be introduced only in the add-on.

Libraries

This section provides detailed lists of changes by library.

Bluetooth libraries and services

Libraries for NFC

  • Parser for messages and records:

    • Fixed an issue where parsing a malformed long-format NDEF record could produce an incorrect payload length. The parser now validates type, ID, and payload lengths against the remaining input buffer.

Other libraries

Integrations

This section provides detailed lists of changes by integration.

DULT integration

  • Updated the Detecting Unwanted Location Trackers (DULT) integration guide to describe both DULT API variants, the multi-user coexistence workflow, and the serialization of the location-enabled advertising payload. The guide also describes the Accessory Non-owner Service access policy, including access before the accessory is associated with an accessory-locating network.

Google Fast Pair integration

Memfault integration

nRF Cloud integration

MCUboot

The MCUboot fork in nRF Connect SDK (sdk-mcuboot) contains all commits from the upstream MCUboot repository up to and including 8d14eebfe0b7402ebdf77ce1b99ba1a3793670e9, with some nRF Connect SDK specific additions.

The code for integrating MCUboot into nRF Connect SDK is located in the ncs/nrf/modules/mcuboot folder.

The following list summarizes both the main changes inherited from upstream MCUboot and the main changes applied to the nRF Connect SDK specific additions:

  • Added:

    • Support for the nRF54LC10A SoC.

    • Support for compiling multiple image verification keys into MCUboot. The CONFIG_BOOT_SIGNATURE_KEY_FILE Kconfig option accepts a comma-separated list of PEM files. Only public key material is embedded in the bootloader image. This enables a production or development signing custody model in which, for example, an updatable development bootloader can boot images signed with either key, while a production bootloader embeds only the production verification key. MCUboot imgtool adds the keyinfo subcommand and the --name-suffix option for getpub and getpubhash to support multiple keys embedded in the bootloader image.

    • Experimental support for the nRF54LS05A SoC.

  • Updated:

    • The CONFIG_BOOT_ECDSA_NRF_OBERON Kconfig option. This option has been reinstated and is no longer deprecated. It has also been configured as the default ECDSA P-256 implementation for the nRF54LS05A and nRF54LS05B SoCs.

    • MCUboot to feed the watchdog more frequently during the following time-consuming operations to prevent watchdog timeouts:

      • Full slot erase procedures

      • The move-sectors-up loop and sectors-swap loop of the swap-move algorithm

      • The hash calculation loop during image hash calculation

  • Fixed an issue where UICR was not provisioned with monotonic counter structures when SB_CONFIG_MCUBOOT_HARDWARE_DOWNGRADE_PREVENTION was enabled, MCUboot was the only bootloader, and Partition Manager was disabled.

Zephyr

The Zephyr fork in nRF Connect SDK (sdk-zephyr) contains all commits from the upstream Zephyr repository up to and including 684c9e8f32e4373a21098559f748f06915f950c9.

For a complete list of nRF Connect SDK specific commits and cherry-picked commits since v3.4.0, run the following command:

git log --oneline manifest-rev ^ncs-v3.4.0

Additions specific to nRF Connect SDK

Documentation