CVE-2025-15150 | PX4 PX4-Autopilot up to 1.16.0 mavlink_log_handler.cpp log_entry_from_id stack-based overflow (Issue 26118 / EUVD-2025-205529)
A vulnerability was found in PX4 PX4-Autopilot up to 1.16.0. It has been declared as critical. Affected by this issue is the function MavlinkLogHandler::state_listing/MavlinkLogHandler::log_entry_from_id of the file src/modules/mavlink/mavlink_log_handler.cpp. The manipulation results in stack-based buffer overflow.
This vulnerability is identified as CVE-2025-15150. The attack is only possible with local access. There is not any exploit available.
It is best practice to apply a patch to resolve this issue.