Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter `/amcl z_short`.
The vulnerability is triggered by remotely sending a request to change the value of the dynamic parameter `/amcl z_short` to the nav2_amcl process. This operation leads to a use-after-free situation, i.e., reference to a memory area that has already been freed. Such a memory management error (CWE-416) can be exploited by an attacker to execute arbitrary code in the context of the vulnerable process.
An attacker can gain full control over the vulnerable system, including the ability to read and modify data and disrupt its operation (RCE, loss of confidentiality, integrity and availability). In the context of robotic systems, this can lead to takeover of control over a physical device.
Patches available from the manufacturer should be applied according to the references. A fix pull request is available in the ros-navigation/navigation2 repository (PR #4397). It is recommended to restrict network access to ROS2 interfaces only to trusted hosts and to monitor traffic directed to nav2_amcl processes.
Open Robotics Robot Operating System 2 (ROS2) and Nav2 in humble version
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HOpenrobotics Robot Operating System
APPOpenrobotics2
Related vulnerabilities
Use-after-free w ROS2 Nav2 humble — zdalny exploit przez nav2_amcl
Heap overflow w procesie nav2_amcl systemu ROS2 Nav2
Use-after-free w ROS2 Nav2 — zdalny atak przez parametr /amcl z_rand
Use-after-free w ROS2 Nav2 humble poprzez proces nav2_amcl
Use-after-free w ROS2 Nav2 — zdalny atak przez zmianę parametru AMCL