LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 October 2021 | | Platform | Quiet Systems | | Series | DKSR-M-2021-10 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF PX4’s MAVLink receiver overflows on TRAJECTORY_REPRESENTATION_WAYPOINTS (msgid 332). Crash of the flight stack. Fix PR the same day. CVE number is 2023. ### Key judgments 1. **[Assessment — High confidence]** Issue #18369 and PR #18371 on 6 October 2021. 2. **[Assessment — High confidence]** This is in-window PX4 memory safety on a MAVLink command path. 3. **[Assessment — High confidence]** CVE-2021-46896 NVD 6 July 2023 is catalogue, not this month. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. PX4 #18369: MAVLink msgid 332 buffer overflow *Event / publication dates: 6 October 2021 (issue and fix PR). CVE-2021-46896 NVD 6 July 2023 not used for dating.* | Field | Value | | --- | --- | | Component | software | | Product | PX4-Autopilot (reporter: SITL and px4_fmu-v5 / nxp_fmuk66-v3) | | CVE / advisory | no CVE in 2021. Later CVE-2021-46896. #18369 / PR #18371 | | Patch | available — same-day PR; reporter confirmed crash gone | | Exploit status | public writeup. Later catalogued | | Taxonomy | CWE-120 (class) · ATT&CK ICS T0814 · OWASP IoT I2 | **Verified record — [Fact — A1] https://github.com/PX4/PX4-Autopilot/issues/18369** **Exposure.** Oversized valid_points crashes the autopilot. Loss of C2 / flight-stack DoS. **Intelligence assessment.** [Assessment — High confidence] GitHub-first date, class, and same-day patch. **Opportunity.** Do not file July 2023 as a new PX4 overflow. Passport ≥ the 18371 commit. **LRRK relevance.** Control Fabric. **Confidence.** High. ## Forward indicators 1. CVE-2021-46896 catalogue (July 2023) — index only. 2. Later SERIAL_CONTROL overflow cluster (2024–2026) — same stack, different message. > **Collection integrity.** Sample packet in the issue is not reproduced here. No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>