CVE-2026-102809
PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the wr
CVSS
6.5
Medio
EPSS
—
KEV
—
Exploit Today
0
0-100
Publicado: 29 sept 2026 · Última mod.: 29 sept 2026 · CWE-789
Sin historial EPSS suficiente todavía.
PX4 Autopilot through 1.17.0 contains an uncontrolled stack allocation vulnerability in the file2 test command that fails to validate the write chunk size parameter. Attackers with shell access can supply an excessively large value to the -c option to trigger stack overflow and crash the flight controller.
- github.comhttps://github.com/PX4/PX4-Autopilot
- github.comhttps://github.com/PX4/PX4-Autopilot/blob/d6f12ad1c4f70ad3230afd7d86e971421e02fef4/src/systemcmds/tests/test_file2.c#L86-L130
- github.comhttps://github.com/PX4/PX4-Autopilot/commit/46a77d8ad15e7929ef261c41083dffd1bbfa9f85
- github.comhttps://github.com/PX4/PX4-Autopilot/pull/28586
- www.vulncheck.comhttps://www.vulncheck.com/advisories/px4-autopilot-through-1.17.0-stack-exhaustion-via-tests-file2-command
- github.comhttps://github.com/PX4/PX4-Autopilot/pull/28586
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-1028206.2 MED—
——0pageant provides a [PageantStream] type that implements [AsyncRead] and [AsyncWrite] traits and can be used to talk to a running Pageant instance. Prior to pageant 0.2.3, the Windows pageant crate's pageant/src/wmmessage.rs MemoryMap::read function trusts a peer-controlled u32 response length supplied through the 8192-byte Pageant shared-memory mapping reached by AgentClient::connect_pageant. A local process that impersonates the Pageant window can make query_pageant_direct allocate up to approximately 4 GiB and copy beyond the mapped view, reliably crashing a russh client and conditionally exposing adjacent committed memory. This issue is fixed in pageant 0.2.3.14hCVE-2026-925507.5 ALT28.1%
——8A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service.
This issue affects Apache Qpid Broker-J: through 10.1.0.
Users are recommended to upgrade to version 10.1.1, which fixes the issue.5dCVE-2026-883827.5 ALT30.5%
——9hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser.6dCVE-2026-962606.5 MED32.8%
——10Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust server memory and cause a denial of service via a large request body sent to a plugin endpoint.. Mattermost Advisory ID: MMSA-2026-007757dCVE-2026-773227.5 ALT42.2%
——13SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length before ParseMaxMessageLength is applied. An unauthenticated WS or WSS peer can send a frame header declaring an extremely large payload, causing an oversized allocation or a makeslice length panic before the payload is read and crashing or exhausting memory in the server process. This issue is fixed in version 1.4.3.7dCVE-2026-599917.5 ALT41.7%
——13psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header geometry, including width, height, channels, depth, and per-layer rectangles, before validating those values against the available file data. A tiny crafted PSD could therefore cause multi-gigabyte memory allocation, and PSDImage.composite() could return a black image with only a warning instead of raising an exception. Services that composite untrusted PSD files could be terminated by out-of-memory handling. This issue is fixed in version 1.17.4.7d