CVE-2026-86096: PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task Startup

Published Sep 4, 2026
·
Updated

PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the calibration process via shell commands to write to freed heap memory, corrupting unrelated objects or allocator metadata and destabilizing heap operations.

Affected Software

1 affected component
PX4 PX4 autopilot<=1.17.0

Event History

Sep 4, 2026
CVE Published
via MITRE·10:38 PM
Data Sourced
via MITRE·10:38 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access does an attacker need to exploit this issue?

The attacker needs the ability to invoke PX4 shell commands that start the temperature calibration process. The provided vector lists no privileges and no user interaction requirements, but exploitation still depends on access to that command interface.

2

What is the likely operational impact?

A successful race can cause writes to freed heap memory, potentially corrupting unrelated objects or allocator metadata. This can destabilize heap operations and cause a denial of service; the supplied severity vector also indicates low integrity impact.

3

Which versions should be considered affected?

PX4 Autopilot versions through 1.17.0 are identified as affected. The provided information does not specify the first fixed release.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203