top of page
perceptive_background_267k.jpg

PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized variable-length known packet and copies it i…

Published:

15 maart 2026 om 23:00:00

Alert date:

16 maart 2026 om 21:03:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Critical Infrastructure

CVE-2026-32706 is a buffer overflow vulnerability in PX4 autopilot flight control solution for drones. The crsf_rc parser accepts oversized variable-length packets and copies them into a fixed 64-byte global buffer without bounds checking. This allows adjacent/raw-serial attackers to trigger memory corruption and crash PX4 systems when crsf_rc is enabled on CRSF serial ports. The vulnerability affects versions prior to 1.17.0-rc2 and has been fixed in version 1.17.0-rc2.

Technical details

Mitigation steps:

Affected products:

PX4 Autopilot

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page