PT-2026-25390 · Px4+2 · Px4-Autopilot+1
Kmm2003
·
Publicado
2026-03-13
·
Atualizado
2026-03-23
·
CVE-2026-32707
CVSS v3.1
6.1
Média
| Vetor | AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PX4 autopilot versions prior to 1.17.0-rc2
Description
PX4 autopilot is a flight control solution for drones. The
tattu can component contains an unbounded memcpy function within its multi-frame assembly loop. This allows for stack memory overwrite when specifically crafted CAN frames are processed. If tattu can is enabled and running, an attacker capable of CAN injection can cause a crash (Denial of Service) and memory corruption.Recommendations
Versions prior to 1.17.0-rc2 should be updated to version 1.17.0-rc2 or later.
Exploit
Correção
Stack Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Px4-Autopilot
Px4 Drone Autopilot