PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can invoke sd_bench with a block size below four bytes to overflow the heap buffer and potentially execute code or crash the system.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can invoke sd_bench with a block size below four bytes to overflow the heap buffer and potentially execute code or crash the system. | |
| Title | PX4 Autopilot sd_bench Heap Buffer Overflow via Block Size | |
| First Time appeared |
Px4
Px4 autopilot |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:px4:autopilot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Px4
Px4 autopilot |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-02T00:37:53.694Z
Updated: 2026-09-04T02:21:07.947Z
Reserved: 2026-09-01T23:24:25.508Z
Link: CVE-2026-84698
Updated: 2026-09-04T02:21:00.697Z
Status : Received
Published: 2026-09-02T01:17:24.850
Modified: 2026-09-04T03:17:44.877
Link: CVE-2026-84698
No data.