CRITICAL🇵🇱 Wersja polska

CVE-2024-38924

CVSS 9.8v3.1pub. 2024-12-06upd. 2024-12-17

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl laser_model_type` .

🤖 AI Analysis
How it works

The vulnerability is triggered by remotely sending a request to change the value of the dynamic parameter `/amcl laser_model_type` in the nav2_amcl process. This operation causes a reference to a memory area that has already been freed (use-after-free), leading to uncontrolled program behavior. An attacker does not need to possess any privileges or user interaction to trigger this error.

Impact

An attacker can gain full control over the system — including confidentiality, integrity, and availability of data — through remote code execution (RCE) or destabilization of the robot control process.

Mitigation & patch

Patches available from the vendor should be applied according to the references — a fix has been proposed in pull request #4397 in the ros-navigation/navigation2 repository. It is recommended to monitor official Nav2 project updates and restrict network access to ROS2 interfaces only to trusted hosts.

Who is affected

Open Robotics Robot Operating System 2 (ROS2) and Nav2 in humble version

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Openrobotics Robot Operating System

    APP
    Openrobotics
    2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2024-38925CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 — zdalny atak przez zmianę parametru AMCL

CVE-2024-38922CRITICAL9.8PL ✓same product

Heap overflow w procesie nav2_amcl systemu ROS2 Nav2

CVE-2024-38921CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 — zdalny atak przez parametr /amcl z_rand

CVE-2024-38923CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 humble poprzez proces nav2_amcl

CVE-2024-38926CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 humble via proces nav2_amcl