CVE-2026-86714
Dashboard / Vulnerabilities / CVE-2026-86714
CVE-2026-86714
Summary: PX4 Autopilot through 1.17.0 Stack Buffer Over-read via netman
Details: PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read beyond buffer boundaries, leaking stack memory to console output or writing it into persistent network configuration files.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86714.json, https://nvd.nist.gov/vuln/detail/CVE-2026-86714, https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-stack-buffer-over-read-via-netman, https://github.com/PX4/PX4-Autopilot/commit/fec216e9d716d96d93b9d882b0c9cf00db3c6810, https://github.com/PX4/PX4-Autopilot/pull/28483, https://github.com/PX4/PX4-Autopilot, https://github.com/PX4/PX4-Autopilot/blob/v1.17.0/src/systemcmds/netman/netman.cpp
Affected packages
Package
Name:
Purl:
