CVE-2024-38920: Use After Free
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2amcl process. This vulnerability is triggerd via remotely sending a request for change the value of dynamic-parameter/amcl maxbeams .
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38920?
CVE-2024-38920 is considered a high severity vulnerability due to its potential impact on system stability and security.
How do I fix CVE-2024-38920?
To fix CVE-2024-38920, update to the latest versions of Open Robotics Robotic Operating System 2 (ROS2) and Nav2 that contain the patched code.
What is the impact of CVE-2024-38920?
The impact of CVE-2024-38920 can lead to a use-after-free condition which may allow remote attackers to perform arbitrary actions on the system.
Which versions of software are affected by CVE-2024-38920?
CVE-2024-38920 affects humble versions of Open Robotics Robotic Operating System 2 (ROS2) and Nav2.
How does CVE-2024-38920 get triggered?
CVE-2024-38920 is triggered by sending a request to change the value of the dynamic parameter `/amcl max_beams` via the nav2_amcl process.