LC-2 · Software Danger Reports
LrrK Kinematic Software Danger Report
Source-imported record. This page is not a QSVFF-sealed filing or a verification certificate.
# LrrK Kinematic Software Danger Report **LRRK Watch / Software Assurance** — Monthly filing. | Field | Value | | --- | --- | | Collection cutoff | 31 August 2025 | | Platform | Quiet Systems | | Series | DKSR-M-2025-08 | | Status | short | | Data label | Open-source intelligence // LRRK analytic product | | Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. | ## Executive read ### BLUF PX4 SERIAL_CONTROL grows a use-after-free ID: CVE-2025-9020. Same handler family as the 2024 overflow. ### Key judgments 1. **[Assessment — High confidence]** NVD published 15 August 2025; CNA lists 1.15.0–1.15.4. 2. **[Uncertainty]** Identity with March 2026 GHSA-j5w2 / CVE-2026-32724 is same-function-family, later separate CVE — do not merge. 3. **[Assessment — High confidence]** CNA: local, high complexity, difficult. Not KEV. ### Analytic labels - **Fact** — verified reporting or primary record - **Assessment** — analytic judgment - **Inference** — reasoned but not directly observed - **Uncertainty** — unresolved information gap ### Source grades - **A1** — authoritative primary record / directly confirmed - **B1–B2** — generally reliable and corroborated - **C3** — useful but requires caution ## 01. CVE-2025-9020: PX4 Mavlink shell use-after-free *Event / publication dates: NVD 15 August 2025* | Field | Value | | --- | --- | | Component | software | | Product | PX4-Autopilot up to 1.15.4 (CNA 1.15.0–1.15.4) | | CVE / advisory | CVE-2025-9020 (VulDB VDB-320081) | | Patch | commit 4395d4f00c49b888f030f5b43e2a779f1fa78708 | | Exploit status | catalogued. Not KEV. | | Taxonomy | ATT&CK ICS T0814 · OWASP IoT I2 | **Verified record — [Fact — A1] https://nvd.nist.gov/vuln/detail/CVE-2025-9020 · https://github.com/PX4/PX4-Autopilot/issues/25046** **Exposure.** Race / UAF in the Mavlink shell closing handler. C2 availability. **Intelligence assessment.** [Assessment — High confidence] Same SERIAL_CONTROL campaign as 2024-07. [Uncertainty] Do not merge with CVE-2026-32724. **Opportunity.** Passport SERIAL_CONTROL patch level across 40427 / 9020 / 32724. **LRRK relevance.** Control Fabric. Watch the cluster, not the CVE count. **Confidence.** High on CVE/date. Moderate on identity with the 2026 GHSA. ## Forward indicators 1. CVE-2026-32724 (March 2026) — same family, separate ID. 2. ArduPilot SERIAL_CONTROL OOB (July 2026). > **Collection integrity.** One ID. PX4 CI workflow GHSAs from this month were excluded (not vehicle stack). No exploit steps. *LRRK — security assurance for systems that sense, move, and act.* <p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>