Impact
PX4 Autopilot up to version 1.17.0 contains a use‑after‑free flaw in the load_mon module’s stop path. When the stop command is processed, the LoadMon object is destroyed and its performance counter freed before the cleanup routine still tries to access that memory. This leads to reads and writes on freed memory, corrupting heap objects and destabilizing the flight stack. The primary consequence is the potential for an attacker to execute arbitrary code or cause a crash, compromising the mission integrity and safety of the vehicle.
Affected Systems
PX4 Autopilot for any build through version 1.17.0. The vendor is PX4, product PX4 Autopilot. Devices running this software are affected unless updated beyond that version.
Risk and Exploitability
The CVSS score of 7.1 denotes a high severity. The EPSS score is not available, and the vulnerability is not currently listed in CISA’s KEV catalog. Attackers can trigger the flaw by issuing the load_mon stop command through any PXH or MAVLink shell. This indicates a remote reachability vector requiring access to the PX4 communication interfaces, making the vulnerability exploitable in air‑borne or ground‑based configurations where MAVLink commands are accepted.
OpenCVE Enrichment