ROS2 Navigation Stack (Nav2) Vulnerability
CVE-2024-38922
9.8CRITICAL
What is CVE-2024-38922?
A vulnerability has been identified in the Open Robotics Robot Operating System 2 (ROS2) and the Nav2 Humble version, characterized by a heap overflow in the nav2_amcl process. This vulnerability can be exploited by sending specially crafted messages to the /initialpose component, potentially allowing unauthorized actions within the affected systems. Proper safeguards and security updates are essential for users to mitigate risks associated with this vulnerability.