Home

Description

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the Zenoh uORB subscriber allocates a stack VLA directly from the incoming payload length without bounds. A remote Zenoh publisher can send an oversized fragmented message to force an unbounded stack allocation and copy, causing a stack overflow and crash of the Zenoh bridge task. This vulnerability is fixed in 1.17.0-rc2.

PUBLISHED Reserved 2026-03-13 | Published 2026-03-13 | Updated 2026-03-13 | Assigner GitHub_M




HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-121: Stack-based Buffer Overflow

Product status

< 1.17.0-rc2
affected

References

github.com/...opilot/security/advisories/GHSA-69g4-hcqf-j45p

cve.org (CVE-2026-32708)

nvd.nist.gov (CVE-2026-32708)

Download JSON