---
id: CVE-2026-102809
title: >-
  PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation
  vulnerability in the file2 test command that fails to validate the write chunk
  size parameter
summary: >-
  PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation
  vulnerability in the file2 test command that fails to validate the write chunk
  size parameter. Attackers with shell access can supply an excessively large
  value to th…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-789
vendor: PX4
product: PX4-Autopilot
affected:
  - PX4-Autopilot <= 1.17.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T19:17:23.657'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102809'
references:
  - url: 'https://github.com/PX4/PX4-Autopilot'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/tests/test_file2.c#L86-L130
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/PX4/PX4-Autopilot/commit/46a77d8ad15e7929ef261c41083dffd1bbfa9f85
    label: disclosure@vulncheck.com
  - url: 'https://github.com/PX4/PX4-Autopilot/pull/28586'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-stack-exhaustion-via-tests-file2-command
    label: disclosure@vulncheck.com
  - url: 'https://github.com/PX4/PX4-Autopilot/pull/28586'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-29T18:13:24.208499Z'
ingestedAt: '2026-09-29T17:41:02.257Z'
---

## Overview

PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the write chunk size parameter. Attackers with shell access can supply an excessively large value to the -c option to trigger stack overflow and crash the flight controller.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
