From 562d10e20f13713fcdece75a7c400d030c8a01c7 Mon Sep 17 00:00:00 2001 From: Peter Barker Date: Tue, 16 Jun 2026 19:11:34 +1000 Subject: [PATCH] AP_MAVLinkCAN: reject negative CAN bus index in filter modify A malformed CAN_FILTER_MODIFY message with a bus value of zero produces bus == -1 after the off-by-one adjustment. The existing bounds check only tested the upper bound, so hal.can[-1] was dereferenced before validation. Add a lower-bound check, matching the fix applied to MAV_CMD_CAN_FORWARD. Co-Authored-By: Claude Opus 4.8 --- libraries/AP_CANManager/AP_MAVLinkCAN.cpp | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/libraries/AP_CANManager/AP_MAVLinkCAN.cpp b/libraries/AP_CANManager/AP_MAVLinkCAN.cpp index 12dfd5879db..ecf1cdb60fe 100644 --- a/libraries/AP_CANManager/AP_MAVLinkCAN.cpp +++ b/libraries/AP_CANManager/AP_MAVLinkCAN.cpp @@ -207,7 +207,7 @@ void AP_MAVLinkCAN::_handle_can_filter_modify(const mavlink_message_t &msg) mavlink_can_filter_modify_t p; mavlink_msg_can_filter_modify_decode(&msg, &p); const int8_t bus = int8_t(p.bus)-1; - if (bus >= HAL_NUM_CAN_IFACES || hal.can[bus] == nullptr) { + if (bus < 0 || bus >= HAL_NUM_CAN_IFACES || hal.can[bus] == nullptr) { return; } if (p.num_ids > ARRAY_SIZE(p.ids)) {