PT-2026-26168 · Px4 · Px4

Zhangteng0526

·

Publicado

2026-03-18

·

Atualizado

2026-03-21

·

CVE-2026-32743

CVSS v3.1

6.5

Média

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PX4 versions 1.17.0-rc2 and below
Description PX4 is an open-source autopilot stack for drones and unmanned vehicles. A stack-based buffer overflow exists through the MavlinkLogHandler, triggered via a MAVLink log request. The LogEntry.filepath buffer is 60 bytes, but the sscanf function parses paths from the log list file without a width specifier, allowing paths exceeding 60 characters to overflow the buffer. An attacker with MAVLink link access can trigger this by creating deeply nested directories via MAVLink FTP, then requesting the log list. This causes the flight controller MAVLink task to crash, resulting in a denial-of-service (DoS) condition and loss of telemetry and command capability.
Recommendations Versions prior to 1.17.0-rc2 should be updated.

Exploit

Correção

Stack Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-32743
GHSA-97C4-68R9-96P5

Produtos afetados

Px4