GHSA-6x78-rh4h-q7jxMediumCVSS 5.4

PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system...

Published
September 8, 2026
Last Modified
September 8, 2026

🔗 CVE IDs covered (1)

📋 Description

PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read beyond buffer boundaries, leaking stack memory to console output or writing it into persistent network configuration files.

🔗 References (7)