Px4

Autopilot

8 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 29.09.2026 17:22:41
  • Zuletzt bearbeitet 02.10.2026 13:17:24

PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability in the sd_stress command where the -b byte count parameter is parsed without validation before being passed to malloc() and memset(). Attackers with shell access, includin...

  • EPSS 0.48%
  • Veröffentlicht 29.09.2026 17:22:41
  • Zuletzt bearbeitet 30.09.2026 17:23:08

PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the write chunk size parameter. Attackers with shell access can supply an excessively large value to the -c option t...

  • EPSS 0.21%
  • Veröffentlicht 08.09.2026 11:23:06
  • Zuletzt bearbeitet 14.09.2026 20:17:01

PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply interface names of 74 bytes or more via the -i option to read beyond buffer b...

  • EPSS 0.37%
  • Veröffentlicht 08.09.2026 11:23:05
  • Zuletzt bearbeitet 08.09.2026 19:54:50

PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter before perf_end() attempts to access it. Attackers can trigg...

  • EPSS 0.24%
  • Veröffentlicht 04.09.2026 22:38:47
  • Zuletzt bearbeitet 10.09.2026 15:43:03

PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. Attackers can invoke 'param select' or 'param selec...

  • EPSS 0.22%
  • Veröffentlicht 04.09.2026 22:38:46
  • Zuletzt bearbeitet 10.09.2026 16:18:01

PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the calibration process via shell commands to write to fr...

  • EPSS 0.27%
  • Veröffentlicht 02.09.2026 00:37:53
  • Zuletzt bearbeitet 10.09.2026 15:43:03

PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can invoke sd_bench with a block size below four bytes to overflow the heap buff...

Medienbericht
  • EPSS 0.93%
  • Veröffentlicht 31.03.2026 20:20:06
  • Zuletzt bearbeitet 29.07.2026 19:31:46

The MAVLink communication protocol does not require cryptographic authentication by default. When MAVLink 2.0 message signing is not enabled, any message -- including SERIAL_CONTROL, which provides interactive shell access -- can be sent by an una...