{"id":"CVE-2025-15150","summary":"PX4 PX4-Autopilot mavlink_log_handler.cpp log_entry_from_id stack-based overflow","details":"A vulnerability was found in PX4 PX4-Autopilot up to 1.16.0. Affected by this issue is the function MavlinkLogHandler::state_listing/MavlinkLogHandler::log_entry_from_id of the file src/modules/mavlink/mavlink_log_handler.cpp. The manipulation results in stack-based buffer overflow. The attack is only possible with local access. The patch is identified as 338595edd1d235efd885fd5e9f45e7f9dcf4013d. It is best practice to apply a patch to resolve this issue.","modified":"2026-08-12T03:51:24.653076966Z","published":"2025-12-28T19:02:07.960Z","database_specific":{"cwe_ids":["CWE-119","CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15150.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.3"},{"last_affected":"1.3"},{"introduced":"1.4"},{"last_affected":"1.4"},{"introduced":"1.6"},{"last_affected":"1.6"}]}],"cna_assigner":"VulDB"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/15xxx/CVE-2025-15150.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-15150"},{"type":"ADVISORY","url":"https://vuldb.com/?id.338527"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.717323"},{"type":"REPORT","url":"https://github.com/PX4/PX4-Autopilot/issues/26118"},{"type":"REPORT","url":"https://github.com/PX4/PX4-Autopilot/pull/26124"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.338527"},{"type":"FIX","url":"https://github.com/PX4/PX4-Autopilot/pull/26124/commits/338595edd1d235efd885fd5e9f45e7f9dcf4013d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/px4/px4-autopilot","events":[{"introduced":"401d35677f63276ba1957093de86a06a6404920b"},{"last_affected":"6ea3539157ca358c70a515878b77077af7d4611d"}],"database_specific":{"extracted_events":[{"introduced":"1.0"},{"last_affected":"1.0"},{"introduced":"1.1"},{"last_affected":"1.1"},{"introduced":"1.2"},{"last_affected":"1.2"},{"introduced":"1.5"},{"last_affected":"1.5"},{"introduced":"1.7"},{"last_affected":"1.7"},{"introduced":"1.8"},{"last_affected":"1.8"},{"introduced":"1.9"},{"last_affected":"1.9"},{"introduced":"1.10"},{"last_affected":"1.10"},{"introduced":"1.11"},{"last_affected":"1.11"},{"introduced":"1.12"},{"last_affected":"1.12"},{"introduced":"1.13"},{"last_affected":"1.13"},{"introduced":"1.14"},{"last_affected":"1.14"},{"introduced":"1.15"},{"last_affected":"1.15"},{"introduced":"1.16.0"},{"last_affected":"1.16.0"},{"introduced":"0"}],"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:dronecode:px4_drone_autopilot:*:*:*:*:*:*:*:*"}}],"versions":["1.0","1.1","1.10","1.11","1.12","1.13","1.14","1.15","1.16.0","1.2","1.5","1.7","1.8","1.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-15150.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}