CVE-2026-102809: fallo de gravedad alta en PX4-Autopilot
PX4 Autopilot through 1.17.0 Stack Exhaustion via tests file2 Command
Publicada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.1epss 0.5%
probabilidad de explotación
0.5%top 60% de las CVE
explotación observada
noninguna fuente lo reporta
PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the write chunk size parameter. Attackers with shell access can supply an excessively large value to the -c option to trigger stack overflow and crash the flight controller.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Productos afectados
PX4 · PX4-AutopilotCVEs relacionadas — PX4-Autopilot
En el mismo producto, de las más peligrosas a las menos.
CVE-2023-46256MEDIUMPX4-Autopilot Heap Buffer Overflow BugEPSS 0.6%CVE-2023-47625LOWGlobal Buffer Overflow leading to denial of service in PX4-AutopilotEPSS 0.5%CVE-2026-84698HIGHPX4 Autopilot sd_bench Heap Buffer Overflow via Block SizeEPSS 0.4%CVE-2026-86097HIGHPX4 Autopilot through 1.17.0 Null Pointer Dereference via param selectEPSS 0.4%CVE-2026-86713HIGHPX4 Autopilot through 1.17.0 Use-After-Free in load_monEPSS 0.4%CVE-2026-86714MEDIUMPX4 Autopilot through 1.17.0 Stack Buffer Over-read via netmanEPSS 0.3%
Referencias
https://github.com/PX4/PX4-Autopilothttps://github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/tests/test_file2.c#L86-L130https://github.com/PX4/PX4-Autopilot/commit/46a77d8ad15e7929ef261c41083dffd1bbfa9f85https://github.com/PX4/PX4-Autopilot/pull/28586https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-stack-exhaustion-via-tests-file2-command