Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
PX4 autopilot has a global buffer overflow in crsf_rc via oversized variable-length known packet
Vulnerability Description
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, The crsf_rc parser accepts an oversized variable-length known packet and copies it into a fixed 64-byte global buffer without a bounds check. In deployments where crsf_rc is enabled on a CRSF serial port, an adjacent/raw-serial attacker can trigger memory corruption and crash PX4. This vulnerability is fixed in 1.17.0-rc2.
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Vulnerability Title
PX4-Autopilot 缓冲区错误漏洞
Vulnerability Description
PX4-Autopilot是PX4 Autopilot开源的一个无人机自动驾驶系统。 PX4-Autopilot 1.17.0-rc2之前版本存在缓冲区错误漏洞,该漏洞源于crsf_rc解析器接受超长可变长度已知数据包并将其复制到固定缓冲区时未进行边界检查,可能导致内存损坏和PX4崩溃。
CVSS Information
N/A
Vulnerability Type
N/A