Medium severity6.5NVD Advisory· Published Sep 29, 2026
CVE-2026-102808
CVE-2026-102808
Description
PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability in the sd_stress command where the -b byte count parameter is parsed without validation before being passed to malloc() and memset(). Attackers with shell access, including through MAVLink, can supply invalid byte count values to crash the flight controller.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.17.0
Patches
Vulnerability mechanics
References
4- github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/sd_stress/sd_stress.cppnvd
- github.com/PX4/PX4-Autopilot/commit/c865dc9fde14d1391916775153aa271603c3c592nvd
- github.com/PX4/PX4-Autopilot/pull/28795nvd
- www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-null-pointer-dereference-via-sd-stressnvd
News mentions
0No linked articles in our index yet.