CVE-2024-24254: Dronecode PX4 Drone Autopilot

Medium severity, CVSS 4.2. EPSS: 0.4% chance of exploitation in the next 30 days.

PX4 Autopilot 1.14 and earlier, due to the lack of synchronization mechanism for loading geofence data, has a Race Condition vulnerability in the geofence.cpp and mission_feasibility_checker.cpp. This will result in the drone uploading overlapping geofences and mission routes.

Affected products

  • Dronecode PX4 Drone Autopilot: up to and including 1.14.0

Published 2024-02-06. Last modified 2026-06-17.