PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsfrc parser accepts an oversized variable-length known packet and copies it into a fixed 64-byte global buffer without a bounds check. In deployments where crsfrc is enabled on a CRSF serial port, an adjacent/raw-serial attacker can trigger memory corruption and crash PX4. This vulnerability is fixed in 1.17.0-rc2.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32706.json",
"cwe_ids": [
"CWE-120",
"CWE-787"
],
"cna_assigner": "GitHub_M"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32706.json"
[
{
"id": "CVE-2026-32706-8741f513",
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/px4/px4-autopilot/commit/0b6e4687defb353a34201951809efd3f0040a9ba",
"deprecated": false,
"digest": {
"line_hashes": [
"67693136990830957487318119173900356909",
"66619955044416162627791375628789032959",
"82079087948384373130544456721427948334",
"19564699393231592692988065433606806311",
"39839865920697555104405496522726657399",
"65807866290241928387326196575495664293",
"7303528363826701270978354797955542450"
],
"threshold": 0.9
},
"target": {
"file": "src/modules/mavlink/mavlink_ftp.h"
}
},
{
"id": "CVE-2026-32706-9203388c",
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/px4/px4-autopilot/commit/0b6e4687defb353a34201951809efd3f0040a9ba",
"deprecated": false,
"digest": {
"line_hashes": [
"273953935082956037420025022101044574717",
"110601522846328491563493342664872427862",
"34306035577689530466562211034699807319",
"49578622599169832155167781920557990289"
],
"threshold": 0.9
},
"target": {
"file": "src/modules/mavlink/mavlink_ftp.cpp"
}
}
]
"2026-04-12T20:14:05Z"