CVE-2024-38910: Use After Free
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in the nav2amcl process. This vulnerability is triggered via sending a request to change dynamic parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38910?
CVE-2024-38910 is classified as a high severity vulnerability due to its ability to cause a use-after-free condition.
How do I fix CVE-2024-38910?
To fix CVE-2024-38910, update to the latest version of Open Robotics Robotic Operating System 2 and Nav2 that addresses this vulnerability.
What causes CVE-2024-38910?
CVE-2024-38910 is caused by a use-after-free condition triggered by sending a request to change dynamic parameters in the nav2_amcl process.
Which versions are affected by CVE-2024-38910?
CVE-2024-38910 affects certain versions of Open Robotics Robotic Operating System 2 and Nav2, specifically the 'humble' version.
What should I do if I am using affected software for CVE-2024-38910?
If you are using affected software, it is crucial to implement the recommended updates or mitigations as soon as possible to minimize risk.