CVE-2026-32743 - Vulnerability Analysis
MediumCVSS: 6.5Last Updated: March 19, 2026
PX4 - Buffer Overflow
Published: March 19, 2026Updated: March 19, 2026PoC Available
Overview
PX4 autopilot stack <= 1.17.0-rc2 contains a stack-based buffer overflow caused by unchecked sscanf parsing of file paths in MavlinkLogHandler, letting attackers with MAVLink access cause denial of service by crashing the flight controller.
Severity & Score
Severity: Medium
CVSS Score: 6.5
Impact
Attackers can crash the flight controller, causing loss of telemetry and command capability, resulting in denial of service.
Mitigation
Update to the fixed commit 616b25a280e229c24d5cf12a03dbf248df89c474 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-32743
- Severity
- Medium
- CVSS Score
- 6.5
- Type
- buffer_overflow
- Status
- confirmed
CWE
- CWE-121
CVSS Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H