CVE-2024-38922: Critical severity robot operating system (ros) vulnerability
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2amcl process. This vulnerability is triggered via sending a crafted message to the component /initialpose.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38922?
CVE-2024-38922 is classified as a high severity vulnerability due to the potential for a heap overflow attack.
How do I fix CVE-2024-38922?
To fix CVE-2024-38922, update to the latest version of the Open Robotics Robot Operating System 2 that addresses the vulnerability.
Which components are affected by CVE-2024-38922?
CVE-2024-38922 affects the nav2_amcl process within Open Robotics Robot Operating System 2, specifically versions humble and iron.
What kind of attack does CVE-2024-38922 enable?
CVE-2024-38922 allows an attacker to perform a heap overflow by sending a crafted message to the /initialpose component.
Is CVE-2024-38922 exploitable remotely?
Yes, CVE-2024-38922 is exploitable remotely as it requires sending specific messages to the vulnerable process.