---
id: CVE-2026-102808
title: >-
  PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability
  in the sd_stress command where the -b byte count parameter is parsed without
  validation before being passed to malloc() and memset()
summary: >-
  PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability
  in the sd_stress command where the -b byte count parameter is parsed without
  validation before being passed to malloc() and memset(). Attackers with shell
  acc…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-476
vendor: PX4
product: PX4-Autopilot
affected:
  - PX4-Autopilot <= 1.17.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T18:17:14.063'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102808'
references:
  - url: 'https://github.com/PX4/PX4-Autopilot'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/sd_stress/sd_stress.cpp#L186-L204
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/PX4/PX4-Autopilot/commit/c865dc9fde14d1391916775153aa271603c3c592
    label: disclosure@vulncheck.com
  - url: 'https://github.com/PX4/PX4-Autopilot/pull/28795'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-null-pointer-dereference-via-sd-stress
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T17:41:02.258Z'
---

## Overview

PX4 Autopilot through 1.17.0 contains a NULL pointer dereference vulnerability in the sd_stress command where the -b byte count parameter is parsed without validation before being passed to malloc() and memset(). Attackers with shell access, including through MAVLink, can supply invalid byte count values to crash the flight controller.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
