Code Injection Vulnerability in Robot Operating System 2 Command-Line Tool
CVE-2024-42002

8.6HIGH

What is CVE-2024-42002?

A code injection vulnerability has been identified in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool. This issue affects all ROS 2 distributions from Crystal Clemmys through to Lyrical Luth and Rolling Ridley. The vulnerability stems from the 'hz' verb, which reports the publishing rate of a topic. It accepts a user-provided Python expression via the --filter option and directly passes this input to the eval() function without any sanitization. As a result, a local user can craft and execute arbitrary code by manipulating the input, creating significant security risks for ROS 2 environments.

Affected Version(s)

Robot Operating System 2 (ROS 2) Linux Rolling Ridley

Robot Operating System 2 (ROS 2) Linux Lyrical Luth

Robot Operating System 2 (ROS 2) Linux Kilted Kaiju

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Florencia Cabral Berenfus, Ubuntu Robotics Team
.