Back

MEDIUM

PX4 Autopilot through 1.17.0 Use-After-Free via Temperature Calibration Task Startup

Published Sep 4, 2026

Description

PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the calibration process via shell commands to write to freed heap memory, corrupting unrelated objects or allocator metadata and destabilizing heap operations.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 4, 2026
Updated Sep 10, 2026
Reserved Sep 4, 2026
CISA Vulnrichment
Updated Sep 10, 2026
NVD
Status Awaiting Analysis
Modified Sep 10, 2026
Red Hat
Severity n/a
Public date n/a