CVE-2026-32705: PX4 autopilot BST Device Name Length Can Overflow Driver Buffer
PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, the BST telemetry probe writes a string terminator using a device-provided length without bounds. A malicious BST device can report an oversized devnamelen, causing a stack overflow in the driver and crashing the task (or enabling code execution). This vulnerability is fixed in 1.17.0-rc2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32705?
CVE-2026-32705 has a medium severity rating due to potential buffer overflow vulnerabilities.
How do I fix CVE-2026-32705?
To fix CVE-2026-32705, update your PX4 Autopilot software to version 1.17.0-rc2 or later.
What impact does CVE-2026-32705 have on PX4 autopilot systems?
CVE-2026-32705 can allow a malicious BST device to cause a buffer overflow, potentially compromising system stability.
Is CVE-2026-32705 exploitable remotely?
Yes, CVE-2026-32705 can be exploited remotely if an attacker can interact with the BST telemetry probe.
What software versions are affected by CVE-2026-32705?
Versions of PX4 Autopilot prior to 1.17.0-rc2 are affected by CVE-2026-32705.