Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_rand ` .
The vulnerability is triggered by remotely sending a request to change the value of the dynamic parameter `/amcl z_rand` to the nav2_amcl process. This request leads to a use-after-free situation in which the code references an area of memory that has already been freed. Since the attack vector is network-based, it does not require authentication or user interaction (AC:L, PR:N, UI:N).
An attacker can gain full control over the vulnerable process, potentially leading to disclosure of sensitive data, data modification, or system disruption (loss of confidentiality, integrity, and availability). In the context of robotic systems, this could result in takeover of physical device control.
Patches available from the vendor should be applied according to the references. A related pull request is available in the navigation2 repository (PR #4397). It is also recommended to restrict network access to ROS2 interfaces through firewall or network isolation, so that dynamic parameter change requests are accessible only from trusted hosts.
Open Robotics Robot Operating System 2 (ROS2) and Nav2 version humble
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpenrobotics Robot Operating System
APPOpenrobotics2
Related vulnerabilities
Use-after-free w ROS2 Nav2 — zdalny atak przez zmianę parametru AMCL
Use-after-free w ROS2 Nav2 humble poprzez proces nav2_amcl
Heap overflow w procesie nav2_amcl systemu ROS2 Nav2
Use-after-free w ROS2 Nav2 humble — zdalny exploit przez nav2_amcl
Use-after-free w ROS2 Nav2 humble via proces nav2_amcl