CVE-2024-38927: Use After Free
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter /amcl dobeamskip.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38927?
CVE-2024-38927 is classified as a high-severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2024-38927?
To fix CVE-2024-38927, update to the latest patched versions of Open Robotics Robotic Operating System 2 (ROS2) and Nav2.
What are the affected versions in CVE-2024-38927?
CVE-2024-38927 affects Open Robotics Robot Operating System 2 versions 2-humble and 2-iron.
What is the exploit mechanism for CVE-2024-38927?
CVE-2024-38927 can be exploited by remotely sending a request to change the dynamic-parameter `/amcl do_beamskip`.
What are the consequences of CVE-2024-38927?
Exploitation of CVE-2024-38927 may lead to system crashes or remote code execution due to the use-after-free issue.