CVE-2024-44855: Null Pointer Dereference
Published Dec 6, 2024
·Updated
Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2navfnplanner().
Affected Software
2 affected components
Openrobotics Robot Operating System=2-humble
Openrobotics Robot Operating System=2-iron
Event History
Dec 6, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-44855?
CVE-2024-44855 is classified as a moderate severity vulnerability due to its potential to cause a NULL pointer dereference.
2
How do I fix CVE-2024-44855?
To mitigate CVE-2024-44855, updating to a fixed version of the ROS2 navigation2 package is recommended.
3
Which versions of ROS2 are affected by CVE-2024-44855?
CVE-2024-44855 affects the ROS2 navigation2 versions 2-humble and 2-iron.
4
What component is involved in CVE-2024-44855?
CVE-2024-44855 involves the nav2_navfn_planner() component within the navigation2 package.
5
What type of vulnerability is CVE-2024-44855?
CVE-2024-44855 is a NULL pointer dereference vulnerability, which can lead to application crashes.