CVE-2024-38925: Use After Free
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter/amcl zmax .
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38925?
CVE-2024-38925 is classified as a moderate severity vulnerability due to its potential to be exploited remotely.
How do I fix CVE-2024-38925?
To fix CVE-2024-38925, update to the latest version of Open Robotics Robot Operating System 2 that addresses this vulnerability.
What causes the CVE-2024-38925 vulnerability?
CVE-2024-38925 is caused by a use-after-free error in the nav2_amcl process when changing the dynamic parameter '/amcl z_max'.
Which versions of Open Robotics Robot Operating System are affected by CVE-2024-38925?
CVE-2024-38925 affects the 2-humble and 2-iron versions of Open Robotics Robot Operating System.
Can CVE-2024-38925 be exploited remotely?
Yes, CVE-2024-38925 can be exploited remotely by sending a request to change the dynamic parameter.