Use-After-Free Vulnerability in ROS2 and Nav2
CVE-2024-38924

9.8CRITICAL

Key Information:

Vendor
CVE Published:
6 December 2024

What is CVE-2024-38924?

A vulnerability has been identified in Open Robotics' Robotic Operating System 2 (ROS2) and its Nav2 navigation framework, specifically in the humble versions. The issue arises due to a use-after-free condition that can be exploited through the nav2_amcl process. This vulnerability occurs when an attacker remotely sends a request to alter the value of the dynamic parameter /amcl laser_model_type, potentially leading to unpredictable behavior and affecting the overall system integrity. Immediate attention and remediation are necessary to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.