Medium severity6.5NVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026
CVE-2026-102809
CVE-2026-102809
Description
PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the write chunk size parameter. Attackers with shell access can supply an excessively large value to the -c option to trigger stack overflow and crash the flight controller.
Affected products
1- Range: <=1.17.0
Patches
Vulnerability mechanics
References
4- github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/tests/test_file2.cnvd
- github.com/PX4/PX4-Autopilot/commit/46a77d8ad15e7929ef261c41083dffd1bbfa9f85nvd
- github.com/PX4/PX4-Autopilot/pull/28586nvd
- www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-stack-exhaustion-via-tests-file2-commandnvd
News mentions
0No linked articles in our index yet.