CVE-2026-102808: high-severity vulnerability in PX4-Autopilot
PX4 Autopilot through 1.17.0 NULL Pointer Dereference via sd_stress
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.1epss 0.2%
exploitation probability
0.2%top 86% of all CVEs
observed exploitation
nono source reports it
PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability in the sd_stress command where the -b byte count parameter is parsed without validation before being passed to malloc() and memset(). Attackers with shell access, including through MAVLink, can supply invalid byte count values to crash the flight controller.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
PX4 · PX4-AutopilotRelated CVEs — PX4-Autopilot
In the same product, most dangerous first.
CVE-2023-46256MEDIUMPX4-Autopilot Heap Buffer Overflow BugEPSS 0.6%CVE-2023-47625LOWGlobal Buffer Overflow leading to denial of service in PX4-AutopilotEPSS 0.5%CVE-2026-102809HIGHPX4 Autopilot through 1.17.0 Stack Exhaustion via tests file2 CommandEPSS 0.5%CVE-2026-84698HIGHPX4 Autopilot sd_bench Heap Buffer Overflow via Block SizeEPSS 0.4%CVE-2026-86097HIGHPX4 Autopilot through 1.17.0 Null Pointer Dereference via param selectEPSS 0.4%CVE-2026-86713HIGHPX4 Autopilot through 1.17.0 Use-After-Free in load_monEPSS 0.4%
References
https://github.com/PX4/PX4-Autopilothttps://github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/sd_stress/sd_stress.cpp#L186-L204https://github.com/PX4/PX4-Autopilot/commit/c865dc9fde14d1391916775153aa271603c3c592https://github.com/PX4/PX4-Autopilot/pull/28795https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-null-pointer-dereference-via-sd-stress