# LrrK Kinematic Software Danger Report

**LRRK Watch / Software Assurance** — Monthly filing.

| Field | Value |
| --- | --- |
| Collection cutoff | 31 May 2026 |
| Platform | Quiet Systems |
| Series | DKSR-M-2026-05 |
| Status | short |
| Data label | Open-source intelligence // LRRK analytic product |
| Handling | Public-source material. Retrospective monthly. Image rights require separate verification before publication. |

## Executive read

### BLUF

DJI published a vendor-commissioned OnDefend assessment of Air 3S and Matrice 4E the same month ArduPilot’s AP_MSP overflow finally hit NVD. An audit is not a CVE.

### Key judgments

1. **[Assessment — High confidence]** Public release 28 May 2026 (PR Newswire). Report dated 14 May 2026 in trade press.
2. **[Assessment — Moderate confidence]** Independence is vendor-commissioned. Zero critical/high/medium in the published summary is a test-window claim, not a national-security finding.
3. **[Assessment — High confidence]** CVE-2024-51394’s public NVD month is May 2026, not the CVE year.

### Analytic labels

- **Fact** — verified reporting or primary record
- **Assessment** — analytic judgment
- **Inference** — reasoned but not directly observed
- **Uncertainty** — unresolved information gap

### Source grades

- **A1** — authoritative primary record / directly confirmed
- **B1–B2** — generally reliable and corroborated
- **C3** — useful but requires caution

## 01. OnDefend assessment of DJI Air 3S / Matrice 4E

*Event / publication dates: DJI PR 28 May 2026; engagement Oct 2025–Mar 2026*

| Field | Value |
| --- | --- |
| Component | software |
| Product | DJI Air 3S + RC 2; Matrice 4E + RC Plus 2 Enterprise; Fly and Pilot 2 |
| CVE / advisory | no CVE. Ten low-risk findings and thirteen observations (published summary). |
| Patch | partial — DJI states collaboration during the engagement |
| Exploit status | none for a critical finding |

**Verified record — [Fact — A1/B2] https://www.prnewswire.com/news-releases/dji-releases-findings-of-the-most-comprehensive-independent-security-assessment-of-its-drone-systems-to-date-302784397.html**

**Exposure.** Sits against the December 2025 FCC Covered List. Not a substitute for it.

**Intelligence assessment.** [Assessment — High confidence] Publication date established. [Uncertainty] Low as a government national-security review.

**Opportunity.** File as Watch context. Do not treat “no backdoors in window” as a Passport close.

**LRRK relevance.** Watch. Lab would need the actual report, which is not independently reproduced here.

**Confidence.** High on publication. Moderate on independence. Low as a national-security substitute.
## 02. CVE-2024-51394: ArduPilot AP_MSP overflow (NVD date)

*Event / publication dates: NVD 13 May 2026*

| Field | Value |
| --- | --- |
| Component | firmware |
| Product | ArduPilot Copter (commit 92693e02 named in CVE text) |
| CVE / advisory | CVE-2024-51394; GHSA-x98m-wmwv-fjg5 |
| Patch | not stated on NVD; tracker issue 28458 |
| Exploit status | catalogued |

**Verified record — [Fact — A1] https://nvd.nist.gov/vuln/detail/CVE-2024-51394**

**Exposure.** Local DoS in AP_MSP::loop. Flight-stack memory safety.

**Intelligence assessment.** [Assessment — High confidence] NVD month is May 2026. [Uncertainty] Affected-version range is a single named commit.

**Opportunity.** Do not back-date to 2024 for this portfolio’s dating rule.

**LRRK relevance.** Control Fabric (index event).

**Confidence.** High on NVD date. Moderate on version range.

## Forward indicators

1. Public OnDefend full report (summary only at collection).
2. ArduPilot tagged release that names 51394.

> **Collection integrity.** Dating rule is public disclosure month. No exploit steps.

*LRRK — security assurance for systems that sense, move, and act.*

<p align="right"><span style="opacity:0.35;letter-spacing:0.18em;font-size:0.8em">L-C2</span></p>
