CVE-2026-102808: fallo de gravedad alta en PX4-Autopilot
PX4 Autopilot through 1.17.0 NULL Pointer Dereference via sd_stress
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.1epss 0.2%
probabilidad de explotación
0.2%top 86% de las CVE
explotación observada
noninguna fuente lo reporta
PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability in the sd_stress command where the -b byte count parameter is parsed without validation before being passed to malloc() and memset(). Attackers with shell access, including through MAVLink, can supply invalid byte count values to crash the flight controller.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Productos afectados
PX4 · PX4-AutopilotCVEs relacionadas — PX4-Autopilot
En el mismo producto, de las más peligrosas a las menos.
CVE-2023-46256MEDIUMPX4-Autopilot Heap Buffer Overflow BugEPSS 0.6%CVE-2023-47625LOWGlobal Buffer Overflow leading to denial of service in PX4-AutopilotEPSS 0.5%CVE-2026-102809HIGHPX4 Autopilot through 1.17.0 Stack Exhaustion via tests file2 CommandEPSS 0.5%CVE-2026-84698HIGHPX4 Autopilot sd_bench Heap Buffer Overflow via Block SizeEPSS 0.4%CVE-2026-86097HIGHPX4 Autopilot through 1.17.0 Null Pointer Dereference via param selectEPSS 0.4%CVE-2026-86713HIGHPX4 Autopilot through 1.17.0 Use-After-Free in load_monEPSS 0.4%
Referencias
https://github.com/PX4/PX4-Autopilothttps://github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/sd_stress/sd_stress.cpp#L186-L204https://github.com/PX4/PX4-Autopilot/commit/c865dc9fde14d1391916775153aa271603c3c592https://github.com/PX4/PX4-Autopilot/pull/28795https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-null-pointer-dereference-via-sd-stress