CVE-2024-38926: Use After Free
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter /amcl zshort.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38926?
CVE-2024-38926 has a high severity rating due to the potential for arbitrary code execution.
How do I fix CVE-2024-38926?
To fix CVE-2024-38926, update the Open Robotics Robot Operating System to the latest patched version of ROS2.
What versions are affected by CVE-2024-38926?
CVE-2024-38926 affects ROS2 humble and iron versions of the Open Robotics Robot Operating System.
What type of vulnerability is CVE-2024-38926?
CVE-2024-38926 is categorized as a use-after-free vulnerability within the nav2_amcl process.
What can be exploited in CVE-2024-38926?
CVE-2024-38926 can be exploited by remotely sending a request to change the value of the dynamic-parameter '/amcl z_short'.