Stack-based Buffer Overflow in PX4 Autopilot for Drones and Unmanned Vehicles
CVE-2026-32743
What is CVE-2026-32743?
The PX4 Autopilot software, used widely in drones and unmanned vehicles, has a vulnerability that allows for a stack-based buffer overflow. This occurs through the MavlinkLogHandler when the sscanf function processes log file paths without a width specifier, enabling an attacker to overflow the buffer with paths exceeding 60 characters. By exploiting this vulnerability via MAVLink link access, an attacker can create deeply nested directories using MAVLink FTP and subsequently request the log list, leading to a crash of the MAVLink task, which results in a loss of telemetry and command capabilities, effectively causing a denial of service (DoS). A fix has been implemented in the latest commits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PX4-Autopilot <= 1.17.0-rc2
