PX4 Autopilot contains a heap buffer overflow...
High severity
Unreviewed
Published
Sep 2, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Sep 2, 2026
Published to the GitHub Advisory Database
Sep 2, 2026
PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can invoke sd_bench with a block size below four bytes to overflow the heap buffer and potentially execute code or crash the system.
References