CVE-2025-15150
⚪ Do wiadomości
Przepełnienie bufora w PX4-Autopilot umożliwia lokalne wykonanie kodu.
CVSS
5.3
EPSS
0.3%
Exploit
poc
Vendor
dronecode
Opis źródłowy (NVD)
A vulnerability was found in PX4 PX4-Autopilot up to 1.16.0. Affected by this issue is the function MavlinkLogHandler::state_listing/MavlinkLogHandler::log_entry_from_id of the file src/modules/mavlink/mavlink_log_handler.cpp. The manipulation results in stack-based buffer overflow. The attack is only possible with local access. The patch is identified as 338595edd1d235efd885fd5e9f45e7f9dcf4013d. It is best practice to apply a patch to resolve this issue.
buffer-overflow exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2025-12-28 19:15:48 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-06 08:10:00 UTC |
Referencje
- https://github.com/PX4/PX4-Autopilot/issues/26118 ([email protected]) [Exploit]
- https://github.com/PX4/PX4-Autopilot/pull/26124 ([email protected]) [Exploit, Patch]
- https://github.com/PX4/PX4-Autopilot/pull/26124/commits/338595edd1d235efd885fd5e9f45e7f9dcf4013d ([email protected]) [Patch]
- https://vuldb.com/?ctiid.338527 ([email protected]) [Permissions Required, VDB Entry]
- https://vuldb.com/?id.338527 ([email protected]) [Third Party Advisory, VDB Entry]
- https://vuldb.com/?submit.717323 ([email protected]) [Third Party Advisory, VDB Entry]