PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the calibration process via shell commands to write to freed heap memory, corrupting unrelated objects or allocator metadata and destabilizing heap operations.
Metrics
Affected Vendors & Products
References
History
Fri, 04 Sep 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the calibration process via shell commands to write to freed heap memory, corrupting unrelated objects or allocator metadata and destabilizing heap operations. | |
| Title | PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task Startup | |
| First Time appeared |
Px4
Px4 autopilot |
|
| Weaknesses | CWE-416 | |
| CPEs | cpe:2.3:a:px4:autopilot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Px4
Px4 autopilot |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-04T22:38:46.695Z
Updated: 2026-09-04T22:38:46.695Z
Reserved: 2026-09-04T22:17:28.470Z
Link: CVE-2026-86096
No data.
Status : Received
Published: 2026-09-04T23:18:03.377
Modified: 2026-09-04T23:18:03.377
Link: CVE-2026-86096
No data.