CVE-2024-38923: Use After Free
Published Dec 6, 2024
·Updated
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter/amcl odomframeid .
Affected Software
2 affected components
Openrobotics Robot Operating System=2-humble
Openrobotics Robot Operating System=2-iron
Event History
Dec 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38923?
CVE-2024-38923 has been assessed with a high severity due to its potential for remote exploitation.
2
How do I fix CVE-2024-38923?
To fix CVE-2024-38923, update to the latest patched version of ROS2 and Nav2 that addresses the vulnerability.
3
What software versions are affected by CVE-2024-38923?
CVE-2024-38923 affects Open Robotics Robot Operating System 2 (ROS2) humble and iron versions.
4
What type of vulnerability is CVE-2024-38923?
CVE-2024-38923 is classified as a use-after-free vulnerability.
5
How can CVE-2024-38923 be triggered?
CVE-2024-38923 can be triggered remotely by sending a request to change the dynamic parameter '/amcl odom_frame_id'.