Files
ardupilot/libraries/AP_VideoTX
Peter BarkerandClaude Opus 4.8 9a7c74e3fb AP_VideoTX: clamp SmartAudio power level count from the wire
unpack_settings() for the v2.1 extended response frame copied
num_power_levels+1 bytes into the fixed power_levels[8] array, where
num_power_levels comes straight from the wire and is unbounded.  A
malformed frame could request a copy of up to 256 bytes, overrunning
both the source and destination arrays.

Clamp the count to the size of the arrays before copying.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-05-31 12:33:22 +10:00
..