Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl laser_model_type` .
The vulnerability is triggered by remotely sending a request to change the value of the dynamic parameter `/amcl laser_model_type` in the nav2_amcl process. This operation causes a reference to a memory area that has already been freed (use-after-free), leading to uncontrolled program behavior. An attacker does not need to possess any privileges or user interaction to trigger this error.
An attacker can gain full control over the system — including confidentiality, integrity, and availability of data — through remote code execution (RCE) or destabilization of the robot control process.
Patches available from the vendor should be applied according to the references — a fix has been proposed in pull request #4397 in the ros-navigation/navigation2 repository. It is recommended to monitor official Nav2 project updates and restrict network access to ROS2 interfaces only to trusted hosts.
Open Robotics Robot Operating System 2 (ROS2) and Nav2 in humble version
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpenrobotics Robot Operating System
APPOpenrobotics2
Related vulnerabilities
Use-after-free w ROS2 Nav2 — zdalny atak przez zmianę parametru AMCL
Heap overflow w procesie nav2_amcl systemu ROS2 Nav2
Use-after-free w ROS2 Nav2 — zdalny atak przez parametr /amcl z_rand
Use-after-free w ROS2 Nav2 humble poprzez proces nav2_amcl
Use-after-free w ROS2 Nav2 humble via proces nav2_amcl