PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can invoke sd_bench with a block size below four bytes to overflow the heap buffer and potentially execute code or crash the system.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 02 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can invoke sd_bench with a block size below four bytes to overflow the heap buffer and potentially execute code or crash the system. | |
| Title | PX4 Autopilot sd_bench Heap Buffer Overflow via Block Size | |
| First Time appeared |
Px4
Px4 autopilot |
|
| Weaknesses | CWE-787 | |
| CPEs | cpe:2.3:a:px4:autopilot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Px4
Px4 autopilot |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-02T00:37:53.694Z
Reserved: 2026-09-01T23:24:25.508Z
Link: CVE-2026-84698
No data.
Status : Received
Published: 2026-09-02T01:17:24.850
Modified: 2026-09-02T01:17:24.850
Link: CVE-2026-84698
No data.
OpenCVE Enrichment
Updated: 2026-09-02T04:00:09Z
Weaknesses