CVE-2024-38921: Use After Free
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter/amcl zrand .
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38921?
CVE-2024-38921 is classified as a high-severity vulnerability due to potential remote exploitation.
How do I fix CVE-2024-38921?
To mitigate CVE-2024-38921, upgrade your Open Robotics Robot Operating System and Nav2 to the latest patched versions.
What systems are affected by CVE-2024-38921?
CVE-2024-38921 affects Open Robotics Robot Operating System 2 versions 2-humble and 2-iron.
What type of vulnerability is CVE-2024-38921?
CVE-2024-38921 is a use-after-free vulnerability that can be triggered via remote parameter changes.
How can CVE-2024-38921 be exploited?
CVE-2024-38921 can be exploited by remotely sending a request to change the dynamic parameter `/amcl z_rand`.