Heap Buffer Overflow in PX4 Autopilot's sd_bench Command
CVE-2026-84698

7.1HIGH

Key Information:

Vendor

Px4

Vendor
CVE Published:
2 September 2026

What is CVE-2026-84698?

The PX4 Autopilot software is susceptible to a heap buffer overflow through the sd_bench command. This vulnerability occurs when an attacker specifies a block size smaller than four bytes, which can lead to corrupted heap memory. This exploitation may allow unauthorized code execution or cause the system to crash, highlighting the importance of securing user input and validating buffer sizes in command-line applications.

Affected Version(s)

PX4-Autopilot 0 <= 1.17.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xiaoyang Chen
.