Use-After-Free Vulnerability Affects ROS2 and Nav2 humble Versions
CVE-2024-38923
9.8CRITICAL
What is CVE-2024-38923?
A vulnerability exists within the Open Robotics Robotic Operating System 2 and Nav2 versions, specifically related to the nav2_amcl process. This issue arises from a use-after-free condition that can be exploited via a remote request aimed at modifying the dynamic parameter /amcl odom_frame_id
. If successfully triggered, this vulnerability could lead to unpredictable behavior and potentially allow for escalation of unauthorized access, impacting the overall integrity of robotic systems relying on these components. Users are recommended to review their configurations and apply necessary updates to mitigate potential security threats.