CVE-2026-32724 - Vulnerability Analysis
MediumCVSS: 5.3Last Updated: March 16, 2026
PX4 autopilot - Use After Free
Published: March 16, 2026Updated: March 16, 2026PoC Available
Overview
PX4 autopilot < 1.17.0-rc1 contains a heap-use-after-free caused by a race condition between MAVLink receiver and telemetry sender threads in MavlinkShell::available(), letting remote attackers cause memory corruption via SERIAL_CONTROL messages.
Severity & Score
Severity: Medium
CVSS Score: 5.3
Impact
Remote attackers can cause memory corruption, potentially leading to denial of service or code execution.
Mitigation
Update to version 1.17.0-rc1 or later.
Related Resources
Details
- CVE ID
- CVE-2026-32724
- Severity
- Medium
- CVSS Score
- 5.3
- Type
- use_after_free
- Status
- confirmed
CWE
- CWE-416
CVSS Metrics
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H