LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 March 2020 | | Platform | Quiet Systems | | Series | DKSR-M-2020-03 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF ArduPilot #13860 is the first in-window public record that MAVLink 2 signing still takes its anti-replay clock from GPS time. Maintainers disputed operational width. ### Key judgments 1. **[Assessment — High confidence]** Issue opened 22 March 2020. Copter 3.5.5 / IRIS+ / Pixhawk1. 2. **[Uncertainty]** Whether a later build still accepts the initial-time set was not re-tested. 3. **[Inference — Moderate confidence]** This is the GPS-time argument the 2026 journal later cites. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. ArduPilot #13860: MAVLink 2 signing vs GPS time *Event / publication dates: 22 March 2020 (GitHub created). Closed 26 March 2020 after discussion.* | Field | Value | | --- | --- | | Component | firmware | | Product | ArduPilot (reporter: Copter 3.5.5 on 3DR IRIS+ / Pixhawk1; reporter states all platforms) | | CVE / advisory | no CVE. ArduPilot/ardupilot#13860 | | Patch | none as a dedicated CVE fix | | Exploit status | public writeup | | Taxonomy | CWE-345 (class) · CAPEC-148 · OWASP IoT I7 | **Verified record — [Fact — A1] https://github.com/ArduPilot/ardupilot/issues/13860** **Exposure.** Signing anti-replay bound to spoofable GNSS time. Sense collapsing Control Fabric. **Intelligence assessment.** [Assessment — High confidence] Mechanism as claimed in the issue. [Uncertainty] Maintainer dispute on operational impact (timestamps only move forward once set). **Opportunity.** Passport the time source for signing. Do not treat “signing on” as enough. **LRRK relevance.** Sense-to-Control-Fabric. **Confidence.** High on the issue. Moderate on later-build width. ## Forward indicators 1. Alias CVE trio (June 2020) — different failure (no auth / downgrade), same protocol. 2. IEEE TComm 2026 journal treatment. > **Collection integrity.** One issue. ATT&CK GNSS technique omitted (no clean official ID). No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>