CVE-2024-44853: Null Pointer Dereference
Published Dec 6, 2024
·Updated
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl().
Affected Software
2 affected components
Openrobotics Robot Operating System=2-humble
Openrobotics Robot Operating System=2-iron
Event History
Dec 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-44853?
CVE-2024-44853 is considered a medium severity vulnerability due to its potential to cause application crashes.
2
How do I fix CVE-2024-44853?
To fix CVE-2024-44853, update the ROBOT OPERATING SYSTEM 2 to the latest version that addresses the NULL pointer dereference issue.
3
Which versions of ROS2 are affected by CVE-2024-44853?
CVE-2024-44853 affects Open Robotics Robot Operating System 2 versions 2-humble and 2-iron.
4
What component is responsible for the vulnerability in CVE-2024-44853?
The vulnerability in CVE-2024-44853 is caused by the computeControl() component.
5
Can CVE-2024-44853 be exploited remotely?
CVE-2024-44853 does not appear to be a remote code execution vulnerability, but it may lead to denial of service via application crashes.