PX4 autopilot is a flight control solution for drones. Prior to 1.17.0-rc2, tattu_can contains an unbounded memcpy in its multi-frame assembly loop, allowing stack memory overwrite when crafted CAN frames are processed. In deployments where tattu_can is enabled and running, a CAN-injection-capable attacker can trigger a crash (DoS) and memory corruption. This vulnerability is fixed in 1.17.0-rc2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-32707. It contains three files: a GPL license, a README with vulnerability description and usage guidance, and a single executable script, exploit.py, which is the sole code artifact and clear entry point. The exploit is not part of a larger framework. The exploit targets PX4-Autopilot versions <= 1.17.0-rc1 when the tattu_can driver is enabled. Its purpose is denial of service, not code execution. The Python script uses the python-can library with SocketCAN to open a user-supplied CAN interface, then transmits a crafted sequence of extended CAN frames on arbitration ID 0x123. First it sends a start-of-transfer frame whose last byte is 0x80, then seven 8-byte frames intended to contribute 7 bytes each to the vulnerable reassembly logic, and finally one more trigger frame. According to the repository documentation and code comments, this causes the driver's cumulative memcpy offset to exceed a 48-byte stack buffer during Tattu12SBatteryMessage reassembly, corrupting the stack and crashing the PX4 process. Operationally, the exploit requires local access to a CAN bus connected to the target or a test environment such as vcan0. The code does not include reconnaissance, target discovery, persistence, or post-exploitation logic. It simply sends the malicious frame sequence and exits. The README provides setup instructions, expected output, affected/fixed versions, and mitigation guidance. Overall, this is a focused, functional DoS PoC for a CAN-bus-reachable stack overflow in PX4's tattu_can driver.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.