Sceawere
Vulnerability Detail
CVE-2026-102808UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
PX4 SD Stress Null Dereference
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 1d ago
- Vendor
- PX4
- Product
- PX4-Autopilot
- Attack Type
- NULL Pointer Dereference
- Vector String
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability in the sd_stress command where the -b byte count parameter is parsed without validation before being passed to malloc() and memset(). Attackers with shell access, including through MAVLink, can supply invalid byte count values to crash the flight controller.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-09-29T18:17:14.063Z",
"pubdate": "2026-09-29T18:17:14.063Z",
"executiveSummary": "PX4 Autopilot through version 1.17.0 is susceptible to a NULL pointer dereference vulnerability within the sd_stress command utility. The flaw originates from the improper handling of user-supplied input for the -b parameter, which specifies the byte count for memory allocation operations.\nThe vulnerability allows an attacker with shell or MAVLink access to trigger a system crash by providing an invalid or out-of-range byte count value. This causes the application to attempt memory operations on an uninitialized or NULL memory space, leading to an immediate service denial.\nThe impact is limited to a flight controller crash (denial of service), which is highly critical in autonomous vehicle environments, as it results in a loss of control over the flight hardware. No evidence suggests remote code execution, but the impact on vehicle safety and availability is severe. Mitigation requires robust input sanitization within the command line parser for the sd_stress component.",
"technicalDetails": "The vulnerability resides in the sd_stress command implementation within the PX4 Autopilot firmware, specifically affecting versions up to and including 1.17.0. The sd_stress utility is designed to perform I/O stress testing on the system's SD card, allowing parameters to be configured via the command line interface.\nThe root cause is a failure to perform input validation on the -b (byte count) argument provided by the user. When the command is invoked, the parser extracts the integer value associated with the -b flag. This value is subsequently passed directly to the standard C library functions malloc() and memset() without checking for sanity, overflow, or boundary conditions. If an attacker provides a value that forces the allocation logic to return a NULL pointer—or fails to validate the return of the allocation attempt before passing it to memset—the system triggers a NULL pointer dereference.\nThe attack flow requires the adversary to obtain an interactive shell or interface with the vehicle via the MAVLink protocol, which is a common communication standard for PX4-based systems. By injecting a crafted sd_stress command string, the attacker triggers the vulnerable code path. The lack of bounds checking allows the attacker to pass arbitrary integers that may cause the memory allocation to fail; if the code fails to verify the success of the allocation before invoking memset(), the system writes to the memory address 0x0, leading to a kernel panic or immediate process termination.\nThis vulnerability is classified as a denial-of-service vector. Since the PX4 Autopilot environment operates as a real-time system, a crash in the primary controller task can lead to loss of attitude control, immediate motor shutdown, or failsafe triggers, potentially resulting in the loss of the aircraft. The exploitation does not necessarily require high-level privileges beyond the ability to execute shell-level commands or command-line instructions reachable through the MAVLink interface."
}