PT-2026-25390 · Px4+2 · Px4-Autopilot+1

Kmm2003

·

Publicado

2026-03-13

·

Atualizado

2026-03-23

·

CVE-2026-32707

CVSS v3.1

6.1

Média

VetorAV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions PX4 autopilot versions prior to 1.17.0-rc2
Description PX4 autopilot is a flight control solution for drones. The tattu can component contains an unbounded memcpy function within its multi-frame assembly loop. This allows for stack memory overwrite when specifically crafted CAN frames are processed. If tattu can is enabled and running, an attacker capable of CAN injection can cause a crash (Denial of Service) and memory corruption.
Recommendations Versions prior to 1.17.0-rc2 should be updated to version 1.17.0-rc2 or later.

Exploit

Correção

Stack Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32707
GHSA-WXWM-XMX9-HR32

Produtos afetados

Px4-Autopilot
Px4 Drone Autopilot