CVE-2023-46256
Summary
| CVE | CVE-2023-46256 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-31 16:15:00 UTC |
| Updated | 2023-11-08 17:53:00 UTC |
| Description | PX4-Autopilot provides PX4 flight control solution for drones. In versions 1.14.0-rc1 and prior, PX4-Autopilot has a heap buffer overflow vulnerability in the parser function due to the absence of `parserbuf_index` value checking. A malfunction of the sensor device can cause a heap buffer overflow with leading unexpected drone behavior. Malicious applications can exploit the vulnerability even if device sensor malfunction does not occur. Up to the maximum value of an `unsigned int`, bytes sized data can be written to the heap memory area. As of time of publication, no fixed version is available. |
Risk And Classification
Problem Types: CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dronecode | Px4 Drone Autopilot | 1.14.0 | beta1 | All | All |
| Application | Dronecode | Px4 Drone Autopilot | 1.14.0 | beta2 | All | All |
| Application | Dronecode | Px4 Drone Autopilot | 1.14.0 | rc1 | All | All |
| Application | Dronecode | Px4 Drone Autopilot | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/PX4/PX4-Autopilot/blob/main/src/drivers/distance_sensor/light... | MISC | github.com | |
| [REPORT] Heap Buffer Overflow Bug Found in src/drivers/distance_sensor/lightware_laser_serial/parser.cpp · Advisory · PX4/PX4-Autopilot · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.