Open-source firmware report

Crazyflie

Firmware for the Crazyflie nano quadcopter.

github.com/bitcraze/crazyflie-firmware · 3 components read from oss-bitcraze__crazyflie-firmware.cdx.json (analysed 2026-10-11) · checked against today's advisories 2026-10-11

Vulnerabilities affecting this build

5reported by a scanner that checks NVD
5reported by Firmpath

Here a scanner that checks NVD reports everything we do that affects this build: these components are well covered by NVD.

1to upgrade
0to look at
0clear
2no advisory source

To upgrade

A published vulnerability affects the version this build uses.

freertos-kernel 10.4.0..10.4.1 Upgrade to 10.6.2 or later5 vulnerabilities · an NVD scanner reports 5
  • CVE-2026-77235 freertos high
    Missing privilege check in SecureContext_FreeContext in FreeRTOS-Kernel
  • CVE-2026-77236 freertos high
    Missing size validation in SecureContext_AllocateContext in FreeRTOS-Kernel
  • CVE-2026-77234 freertos high
    Improper input validation in FreeRTOS-Kernel timer command handling
  • CVE-2024-28115 freertos high
    Potential Privilege Escalation in FreeRTOS Kernel ARMv7-M MPU ports and ARMv8-M ports with MPU support enabled
  • CVE-2026-77237 freertos medium
    Missing type validation in xQueueAddToSet in FreeRTOS-Kernel

No advisory source

No vendor advisory, NVD or OSV record has ever named these. That is not the same as safe: nobody is publishing about them.

How this was made, and what it is not

We read the project's build description (manifests, submodules, the SDK it pins), took each SDK release apart into the libraries it bundles, and compared every version with the ranges in vendors' own advisories, NVD and OSV. Every verdict is computed from versions; each finding links to the document it came from. Missed by NVD scanners means a scanner keyed on NVD's CPE records would not report it for this version: no CVE, no NVD record, or NVD files it under another product. The comparison counts only vulnerabilities affecting the version this build uses.

It describes the repository's default build, not any particular binary, and a project may configure out the affected code. It is not an audit. It is recomputed daily as advisories are published. Also as JSON.