First published: Tue Feb 20 2024(Updated: )
Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Robot Operating System (ROS) | >=humble< | |
Robot Operating System (ROS) | >=humble< |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25199 has a high severity due to its potential for causing use-after-free vulnerabilities in ROS2 and Nav2.
To fix CVE-2024-25199, users should upgrade to the latest patched versions of ROS2 and Nav2 that address this vulnerability.
CVE-2024-25199 affects all versions of Open Robotics Robotic Operating System 2 and Nav2 that are at or above the humble version.
CVE-2024-25199 is caused by an inappropriate pointer order in the map_sub_ and map_free functions within amcl_node.cpp.
CVE-2024-25199 poses a risk that could potentially be exploited remotely, allowing attackers to cause application crashes or execute arbitrary code.