CRITICAL🇵🇱 Wersja polska

CVE-2024-38926

CVSS 9.8v3.1pub. 2024-12-06upd. 2024-12-17

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter `/amcl z_short`.

🤖 AI Analysis
How it works

The vulnerability is triggered by remotely sending a request to change the value of the dynamic parameter `/amcl z_short` to the nav2_amcl process. This operation leads to a use-after-free situation, i.e., reference to a memory area that has already been freed. Such a memory management error (CWE-416) can be exploited by an attacker to execute arbitrary code in the context of the vulnerable process.

Impact

An attacker can gain full control over the vulnerable system, including the ability to read and modify data and disrupt its operation (RCE, loss of confidentiality, integrity and availability). In the context of robotic systems, this can lead to takeover of control over a physical device.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. A fix pull request is available in the ros-navigation/navigation2 repository (PR #4397). It is recommended to restrict network access to ROS2 interfaces only to trusted hosts and to monitor traffic directed to nav2_amcl processes.

Who is affected

Open Robotics Robot Operating System 2 (ROS2) and Nav2 in humble version

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Openrobotics Robot Operating System

    APP
    Openrobotics
    2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Memory
CWE
References

Related vulnerabilities

CVE-2024-38924CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 humble — zdalny exploit przez nav2_amcl

CVE-2024-38922CRITICAL9.8PL ✓same product

Heap overflow w procesie nav2_amcl systemu ROS2 Nav2

CVE-2024-38921CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 — zdalny atak przez parametr /amcl z_rand

CVE-2024-38923CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 humble poprzez proces nav2_amcl

CVE-2024-38925CRITICAL9.8PL ✓same product

Use-after-free w ROS2 Nav2 — zdalny atak przez zmianę parametru AMCL