CVE-2024-25196 Information
Feb 21, 2024
cve
Description
Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file.
Reference
https://github.com/ros-planning/navigation2/issues/4005 https://robotics.stackexchange.com/questions/106008/ros2nav2user-misconfiguration-of-parameters-may-cause-instantaneous-crashs https://github.com/ros-planning/navigation2/pull/4017
Share on: