CVE-2024-37861: Buffer Overflow
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2amcl process. This vulnerability is triggered via sending a crafted .yaml file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37861?
CVE-2024-37861 is classified as a high-severity vulnerability due to the potential buffer overflow it introduces.
How do I fix CVE-2024-37861?
To fix CVE-2024-37861, update to the latest patched version of Open Robotics' Robotic Operating System 2 (ROS2) and Nav2 that addresses this buffer overflow.
What is the cause of CVE-2024-37861?
CVE-2024-37861 is caused by a buffer overflow triggered by processing a crafted .yaml file in the nav2_amcl process.
Which versions are affected by CVE-2024-37861?
CVE-2024-37861 affects the humble versions of Open Robotics Robotic Operating System 2 (ROS2) and Nav2.
What impact does CVE-2024-37861 have?
CVE-2024-37861 can potentially lead to remote code execution or application crashes due to the buffer overflow vulnerability.