← GrokBot Source Archive

LC-2 · Software Danger Reports

LrrK Kinematic Software Danger Report

Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
Recorded date
Date not recorded
Drive source path
quiet-systems-archive/LC-2/months/2026-07.md
Imported-content SHA-256
5be9f4805e9129d03a64a92982ec33357d7804b67b288410f8de63e8db1e9ddd
Imported representation
Drive UTF-8 text
Open original Drive locator ↗ · View source Markdown
# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 July 2026 |
| Platform | Quiet Systems |
| Series | DKSR-M-2026-07 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

ArduPilot gets its own SERIAL_CONTROL CVE. Same message class CISA treated as a PX4 shell in March. The fix merged in March; NVD published in July.

### Key judgments

1. **[Assessment — High confidence]** CVE-2026-38971, NVD 2 July 2026, through Plane-4.6.3.
2. **[Assessment — High confidence]** PR #32587 merged 29 March 2026 — fix before catalogue.
3. **[Uncertainty]** No tagged release beyond Plane-4.6.3 confirmed in the CVE record at collection.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. CVE-2026-38971: ArduPilot SERIAL_CONTROL OOB read

*Event / publication dates: NVD 2 July 2026; PR merged 29 March 2026*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | ArduPilot through Plane-4.6.3 (shared GCS_MAVLink; other vehicles not listed as affected on the CVE text) |
| CVE / advisory | CVE-2026-38971; GHSA-8g74-gp28-fgqv |
| Patch | PR #32587 merged 29 March 2026; tagged release unverified |
| Exploit status | catalogued. CISA-ADP CVSS 9.1 |
| Taxonomy | ATT&CK ICS T0814 · OWASP IoT I2 |

**Verified record — [Fact — A1] https://nvd.nist.gov/vuln/detail/CVE-2026-38971 · https://github.com/ArduPilot/ardupilot/pull/32587**

**Exposure.** OOB read on SERIAL_CONTROL count. Crash or memory leak on a MAVLink-reachable interface.

**Intelligence assessment.** [Assessment — High confidence] Same message class as PX4 2024/2026. [Uncertainty] “through 4.6.3” vs merge after that tag.

**Opportunity.** Passport ArduPilot SERIAL_CONTROL separately from PX4. Watch the tagged release.

**LRRK relevance.** Control Fabric. Kestrel the message, not the brand.

**Confidence.** High.

## Forward indicators

1. First tagged ArduPilot release that is unambiguous for 38971.
2. Other vehicles on shared GCS_MAVLink listed or excluded.

> **Collection integrity.** Catalogue month is July. Merge month noted, not used as the filing month. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>