Junglewise Threat Intelligence

CVE-2024-51395: ArduPilot ArduCopter buffer overflow in AP_SmartAudio

CVE-2024-51395 · Severity: info · Published 2026-05-13

Executive brief

A buffer overflow vulnerability has been identified in ArduPilot ArduCopter, the firmware used to control various types of multirotors and helicopters. An attacker with local access to the system could exploit this flaw to cause the flight controller to crash or become unresponsive. This results in a denial of service, potentially leading to a loss of vehicle control during operation.

Technical details

A stack-based buffer overflow exists in the AP_SmartAudio::loop function within AP_SmartAudio.cpp of the ArduPilot ArduCopter firmware. The vulnerability is triggered during the processing of SmartAudio protocol data, where insufficient bounds checking can lead to a thread stack overflow. A local attacker can exploit this to cause a crash of the firmware (Denial of Service). The issue was identified in commit 92693e023793133e49a035daf37c14433e484778. While the advisory lists the attack vector as local, in the context of drone firmware, this typically implies interaction via local telemetry or peripheral interfaces.

Affected products

  • ArduPilot ArduCopter commit 92693e023793133e49a035daf37c14433e484778

Timeline

  • 2024-10-10: disclosed: Issue reported on GitHub
  • 2026-05-13: advisory: CVE published by NVD

References