CVE-2026-38971 Details
Description
ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle_serial_control().
A buffer overread vulnerability has been identified in ArduPilot versions through Plane-4.6.3. The issue resides in the GCS_MAVLink module, specifically within the handle_serial_control function of the GCS_serial_control.cpp file. The vulnerability stems from an out-of-bounds read, where the SERIAL_CONTROL message can be mishandled, potentially leading to the propagation of uninitialized data.
Users can update to the latest version of ArduPilot, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ArduPilot/ardupilot/issues/32524 | CISA-ADP | ExploitIssue Tracking |
| https://gist.github.com/quart27219/6bfcc615f89fb493d02aad480704593b | [email protected] | |
| https://github.com/ArduPilot/ardupilot | [email protected] | Product |
| https://github.com/ArduPilot/ardupilot/issues/32524 | [email protected] | ExploitIssue Tracking |
| https://github.com/ArduPilot/ardupilot/pull/32587 | [email protected] | Issue TrackingPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| ardupilot arduplane | <= 4.6.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 9, 2026 | CVE Modified | [email protected] |
| Jul 8, 2026 | Initial Analysis | [email protected] |
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 2, 2026 | New CVE Received | [email protected] |