Use-After-Free Vulnerability Affects ROS2 and Nav2 humble Versions
CVE-2024-38923

9.8CRITICAL

Key Information:

Vendor
CVE Published:
6 December 2024

What is CVE-2024-38923?

A vulnerability exists within the Open Robotics Robotic Operating System 2 and Nav2 versions, specifically related to the nav2_amcl process. This issue arises from a use-after-free condition that can be exploited via a remote request aimed at modifying the dynamic parameter /amcl odom_frame_id. If successfully triggered, this vulnerability could lead to unpredictable behavior and potentially allow for escalation of unauthorized access, impacting the overall integrity of robotic systems relying on these components. Users are recommended to review their configurations and apply necessary updates to mitigate potential security threats.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.