CVE-2026-102809
6.5 MEDIUMpublic exploit availablePublished 2026-09-29 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the write chunk size parameter. Attackers with shell access can supply an excessively large value to the -c option to trigger stack overflow and crash the flight controller.
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses
CWE-789
Public exploit & PoC references
- https://github.com/PX4/PX4-Autopilot
- https://github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/tests/test_file2.c#L86-L130
- https://github.com/PX4/PX4-Autopilot/commit/46a77d8ad15e7929ef261c41083dffd1bbfa9f85
- https://github.com/PX4/PX4-Autopilot/pull/28586
- https://github.com/PX4/PX4-Autopilot/pull/28586
All references
- https://github.com/PX4/PX4-Autopilot
- https://github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/tests/test_file2.c#L86-L130
- https://github.com/PX4/PX4-Autopilot/commit/46a77d8ad15e7929ef261c41083dffd1bbfa9f85
- https://github.com/PX4/PX4-Autopilot/pull/28586
- https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-stack-exhaustion-via-tests-file2-command
- https://github.com/PX4/PX4-Autopilot/pull/28586
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-102820PoC
- MEDIUMCVE-2026-15337PoC
- HIGHCVE-2026-47321
- UNSCOREDCVE-2026-58067
- HIGHCVE-2026-58268PoC
- HIGHCVE-2026-59991PoC
- HIGHCVE-2026-61485
- MEDIUMCVE-2026-62370PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.