A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-32708

CVE-2026-32708: PX4 Autopilot Buffer Overflow Vulnerability

CVE-2026-32708 is a buffer overflow vulnerability in Dronecode PX4 Drone Autopilot that enables remote attackers to crash the Zenoh bridge task via oversized messages. This article covers technical details, affected versions, impact, and mitigation.

Updated: May 14, 2026

CVE-2026-32708 Overview

CVE-2026-32708 is a stack-based buffer overflow [CWE-121] in the PX4 Autopilot flight control software for drones. The Zenoh uORB subscriber allocates a stack variable-length array (VLA) directly from the incoming payload length without bounds checking. A remote Zenoh publisher on the adjacent network can transmit an oversized fragmented message to force an unbounded stack allocation and copy. The result is a stack overflow that crashes the Zenoh bridge task on the affected drone. The flaw impacts PX4 Autopilot versions prior to 1.17.0-rc2, including 1.17.0-alpha1, 1.17.0-beta1, and 1.17.0-rc1.

Critical Impact

An authenticated attacker on the adjacent network can crash the Zenoh bridge task on a PX4-controlled drone, causing loss of inter-process telemetry and potential flight disruption.

Affected Products

  • Dronecode PX4 Autopilot versions prior to 1.17.0-rc2
  • PX4 Autopilot 1.17.0-alpha1 and 1.17.0-beta1
  • PX4 Autopilot 1.17.0-rc1

Discovery Timeline

  • 2026-03-16 - CVE-2026-32708 published to NVD
  • 2026-03-17 - Last updated in NVD database

Technical Details for CVE-2026-32708

Vulnerability Analysis

PX4 Autopilot integrates Zenoh, a publish-subscribe networking protocol, to bridge external messages into its uORB inter-process communication layer. The Zenoh uORB subscriber processes incoming messages by allocating a stack-based variable-length array sized according to the attacker-controlled payload length field. The code path performs no upper bound check before the allocation and the subsequent copy operation. When a malicious publisher transmits a fragmented Zenoh message advertising an oversized payload, the subscriber attempts to allocate a VLA far larger than the available stack region. The allocation and copy overrun the task stack, corrupting adjacent memory and crashing the Zenoh bridge task. The fix in version 1.17.0-rc2 introduces explicit length validation against a fixed maximum before any stack allocation occurs.

Root Cause

The root cause is improper input validation on the payload length field of incoming Zenoh messages. The Zenoh uORB subscriber trusts attacker-supplied size data when sizing a stack VLA, violating safe coding practice for boundary checks [CWE-121].

Attack Vector

The attack requires adjacent network access and low privileges on the Zenoh fabric. An attacker registered as a Zenoh publisher on the same network can craft a fragmented message with an inflated payload length. No user interaction on the drone side is needed. Successful exploitation crashes the bridge task and disrupts data flow between Zenoh and uORB subscribers.

No public proof-of-concept exploit has been published. Refer to the PX4 GitHub Security Advisory GHSA-69g4-hcqf-j45p for vendor technical details.

Detection Methods for CVE-2026-32708

Indicators of Compromise

  • Unexpected termination or restart of the Zenoh bridge task in PX4 system logs
  • Stack corruption traces or hard fault entries in the autopilot crash log
  • Inbound Zenoh fragmented messages with payload length fields exceeding normal operational sizes

Detection Strategies

  • Monitor PX4 dmesg output and ULog files for repeated crashes of the Zenoh bridge process
  • Inspect Zenoh network traffic for fragmented frames with anomalously large declared payload sizes
  • Correlate sudden uORB topic dropouts with timestamps of inbound Zenoh sessions from unauthorized peers

Monitoring Recommendations

  • Enable verbose logging on the Zenoh router and archive session metadata for forensic review
  • Track the membership of the Zenoh fabric and alert on new or unrecognized publishers joining the network
  • Capture packet traces at the ground control station to baseline normal Zenoh payload size distribution

How to Mitigate CVE-2026-32708

Immediate Actions Required

  • Upgrade PX4 Autopilot to version 1.17.0-rc2 or later on all affected airframes
  • Restrict Zenoh bridge exposure to trusted network segments only, disabling discovery on untrusted interfaces
  • Audit Zenoh access control lists to confirm only authorized publishers can connect to drone subscribers

Patch Information

The vulnerability is fixed in PX4 Autopilot 1.17.0-rc2. The patch adds bounds enforcement on the incoming payload length in the Zenoh uORB subscriber before any stack allocation. See the PX4 GitHub Security Advisory GHSA-69g4-hcqf-j45p for patch commit references.

Workarounds

  • Disable the Zenoh uORB bridge module if it is not required for the mission profile
  • Deploy Zenoh on an isolated VLAN or encrypted overlay accessible only to authenticated ground control endpoints
  • Configure network-layer filtering to drop oversized Zenoh fragments at the edge of the drone control network
bash
# Configuration example: disable Zenoh bridge at PX4 startup
# Edit the PX4 startup script (e.g., etc/init.d/rc.mc_apps) and comment out:
# zenoh start

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeBuffer Overflow

  • Vendor/TechDronecode Px4 Drone Autopilot

  • SeverityHIGH

  • CVSS Score8.0

  • EPSS Probability0.02%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-121
  • Vendor Resources
  • GitHub Security Advisory
  • Related CVEs
  • CVE-2026-32743: PX4 Autopilot Buffer Overflow Vulnerability

  • CVE-2026-32705: Dronecode PX4 Buffer Overflow Vulnerability

  • CVE-2026-32706: Px4 Drone Autopilot Buffer Overflow Flaw

  • CVE-2026-32707: Dronecode PX4 Autopilot DoS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English