Description
PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter before perf_end() attempts to access it. Attackers can trigger this vulnerability by issuing the load_mon stop command from any PXH or MAVLink shell, causing reads and writes through freed memory that corrupt heap objects and destabilize the flight stack.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

PX4 Autopilot up to version 1.17.0 contains a use‑after‑free flaw in the load_mon module’s stop path. When the stop command is processed, the LoadMon object is destroyed and its performance counter freed before the cleanup routine still tries to access that memory. This leads to reads and writes on freed memory, corrupting heap objects and destabilizing the flight stack. The primary consequence is the potential for an attacker to execute arbitrary code or cause a crash, compromising the mission integrity and safety of the vehicle.

Affected Systems

PX4 Autopilot for any build through version 1.17.0. The vendor is PX4, product PX4 Autopilot. Devices running this software are affected unless updated beyond that version.

Risk and Exploitability

The CVSS score of 7.1 denotes a high severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. Attackers can trigger the flaw by issuing the load_mon stop command through any PXH or MAVLink shell. This indicates a remote reachability vector requiring access to the PX4 communication interfaces, making the vulnerability exploitable in air‑borne or ground‑based configurations where MAVLink commands are accepted.

Generated by OpenCVE AI on September 8, 2026 at 12:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the PX4 firmware to a version newer than 1.17.0 where the load_mon use‑after‑free flaw is fixed.
  • If upgrading is not immediately possible, disable the load_mon module or remove it from the build configuration to eliminate the stop command path.
  • Restrict access to PXH and MAVLink shells or enforce encrypted communication so that only authenticated operators can issue the load_mon stop command.

Generated by OpenCVE AI on September 8, 2026 at 12:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the performance counter before perf_end() attempts to access it. Attackers can trigger this vulnerability by issuing the load_mon stop command from any PXH or MAVLink shell, causing reads and writes through freed memory that corrupt heap objects and destabilize the flight stack.
Title PX4 Autopilot through 1.17.0 Use-After-Free in load_mon
First Time appeared Px4
Px4 autopilot
Weaknesses CWE-416
CPEs cpe:2.3:a:px4:autopilot:*:*:*:*:*:*:*:*
Vendors & Products Px4
Px4 autopilot
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-08T12:20:00.829Z

Reserved: 2026-09-08T10:58:30.836Z

Link: CVE-2026-86713

cve-icon Vulnrichment

Updated: 2026-09-08T12:19:56.063Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T12:17:00.150

Modified: 2026-09-08T19:54:50.793

Link: CVE-2026-86713

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T13:15:03Z

Weaknesses