CVE-2024-42002: Unsafe use of eval() method in ros2 topic hz tool
A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A local user who can run the ros2topic command-line tool can exploit it. The supplied vector has no privileges or user interaction requirements.
What input is required to trigger code execution?
The attacker must invoke the hz verb and provide a crafted Python expression through the --filter option. That expression is passed directly to Python eval() without sanitization.
Which ROS 2 releases are affected?
All ROS 2 distributions from Crystal Clemmys through Lyrical Luth, including Rolling Ridley, are affected according to the available information.