Executive brief
A stack overflow vulnerability exists in the ArduPilot Rover firmware, specifically within the driver for ADIS1647x inertial sensors. This software is used to control autonomous vehicles like rovers and boats. An exploit could cause the vehicle's flight controller to crash or behave unpredictably, leading to a denial of service and potential loss of control over the hardware.
Technical details
A stack overflow vulnerability was identified in the `AP_InertialSensor_ADIS1647x::loop` function of ArduPilot. The firmware allocates a fixed stack size of 1024 bytes for the ADIS1647x sensor thread; however, under specific build configurations (such as those enabling MAVLink signing and SHA256 updates), the call stack depth can reach approximately 1216 bytes. This exhaustion of allocated stack space can lead to memory corruption or a system panic. The issue is triggered during normal sensor processing and MAVLink communication, allowing a local attacker or specific operational conditions to cause a denial of service (DoS). The vulnerability was identified in commit c56439b.
Affected products
- ArduPilot ArduRover commit c56439b045162058df0ff136afea3081fcd06d38
Timeline
- 2024-08-26: disclosed: Issue reported on GitHub repository
- 2026-05-13: advisory: CVE published by NVD