CVE-2024-38924: Use After Free
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter/amcl lasermodeltype .
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38924?
CVE-2024-38924 is classified as a critical vulnerability due to its potential for exploitation which leads to use-after-free conditions.
How do I fix CVE-2024-38924?
To fix CVE-2024-38924, upgrade to the latest versions of the Open Robotics Robotic Operating System 2 that address this vulnerability.
What causes CVE-2024-38924?
CVE-2024-38924 is caused by a use-after-free vulnerability in the nav2_amcl process triggered by remote requests to change dynamic parameters.
Which versions are affected by CVE-2024-38924?
CVE-2024-38924 affects the Open Robotics Robot Operating System 2 humble and iron versions.
What are the implications of CVE-2024-38924 for users?
Users affected by CVE-2024-38924 may experience remote exploitation risks impacting the stability and security of their robotic systems.