Memory Corruption in PX4 Autopilot Flight Control Solution for Drones
CVE-2026-32706
7.1HIGH
What is CVE-2026-32706?
Prior to version 1.17.0-rc2, the PX4 autopilot's crsf_rc parser was vulnerable to a memory corruption issue. By accepting an oversized variable-length known packet and copying it into a fixed 64-byte global buffer without bounds checking, the vulnerability allowed an adjacent/raw-serial attacker to cause memory corruption, potentially leading to a system crash. This issue is addressed in version 1.17.0-rc2, which mitigates the risks associated with this flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PX4-Autopilot < 1.17.0-rc2
