CVE-2026-102808
PX4 Autopilot through 1.17.0 NULL Pointer Dereference via sd_stress
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability in the sd_stress command where the -b byte count parameter is parsed without validation before being passed to malloc() and memset(). Attackers with shell access, including through MAVLink, can supply invalid byte count values to crash the flight controller.
| CWE | CWE-476 |
| Vendor | px4 |
| Product | px4-autopilot |
| Published | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for px4 px4-autopilot
Be the first to know when new medium vulnerabilities affecting px4 px4-autopilot are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
PX4 / PX4-Autopilot
0 โค 1.17.0
References
github.com: https://github.com/PX4/PX4-Autopilot/pull/28795 github.com: https://github.com/PX4/PX4-Autopilot/commit/c865dc9fde14d1391916775153aa271603c3c592 github.com: https://github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/sd_stress/sd_stress.cpp#L186-L204 github.com: https://github.com/PX4/PX4-Autopilot vulncheck.com: https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-null-pointer-dereference-via-sd-stress
Credits
Tianbo Wang Xiaoyang Chen