CVE-2026-38971

CRITICAL

ArduPilot Plane <= 4.6.3 - Out-of-Bounds Read in GCS_MAVLINK::handle_serial_control

Title source: llm
STIX 2.1

Description

ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle_serial_control().

Scores

CVSS v3 9.1
EPSS 0.0051
EPSS Percentile 40.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-125
Status published
Products (1)
ardupilot/arduplane < 4.6.3
Published Jul 02, 2026
Tracked Since Jul 03, 2026