<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – ROS 2</title>
  <link>https://cvedaily.com/pages/tags/ros-2.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/ros-2.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – ROS 2</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:07 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2024-44856 – Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovere...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44856</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44856</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44856</strong></p>
  <p>Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner().</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44856">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44855 – Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovere...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44855</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44855</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44855</strong></p>
  <p>Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_navfn_planner().</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44855">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44854 – Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovere...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44854</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44854</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44854</strong></p>
  <p>Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component smoothPlan().</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44854">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-44853 – Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovere...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44853</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44853</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-44853</strong></p>
  <p>Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl().</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44853">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-44852 – Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovere...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-44852</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-44852</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-44852</strong></p>
  <p>Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::ThetaStar::isUnsafeToPlan().</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-763</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-44852">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-41650 – Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41650</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41650</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-41650</strong></p>
  <p>Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_costmap_2d.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41650">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-41649 – Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41649</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41649</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-41649</strong></p>
  <p>Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the executor_thread_.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41649">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-41648 – Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41648</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41648</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-41648</strong></p>
  <p>Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41648">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-41647 – Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41647</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41647</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-41647</strong></p>
  <p>Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_mppi_controller.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41647">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-41646 – Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41646</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41646</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-41646</strong></p>
  <p>Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_dwb_controller.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41646">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-41645 – Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41645</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-41645</strong></p>
  <p>Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2__amcl.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-41644 – Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 R...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41644</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41644</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-41644</strong></p>
  <p>Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-281</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41644">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38927 – Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38927</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38927</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38927</strong></p>
  <p>Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter `/amcl do_beamskip`.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38927">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38926 – Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38926</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38926</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38926</strong></p>
  <p>Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter `/amcl z_short`.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38926">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38925 – Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38925</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38925</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38925</strong></p>
  <p>Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_max` .</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38925">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38924 – Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38924</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38924</strong></p>
  <p>Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl laser_model_type` .</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38923 – Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38923</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38923</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38923</strong></p>
  <p>Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl odom_frame_id` .</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38923">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38922 – Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was disc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38922</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38922</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38922</strong></p>
  <p>Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is triggered via sending a crafted message to the component /initialpose.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38922">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38921 – Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38921</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38921</guid>
    <pubDate>Fri, 06 Dec 2024 22:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38921</strong></p>
  <p>Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_rand ` .</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38921">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-38920 – Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38920</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38920</guid>
    <pubDate>Thu, 05 Dec 2024 23:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-38920</strong></p>
  <p>Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggerd via remotely sending a request for change the value of dynamic-parameter`/amcl max_beams` .</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38920">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-38910 – Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was disc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38910</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38910</guid>
    <pubDate>Thu, 05 Dec 2024 23:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-38910</strong></p>
  <p>Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a use-after-free in the nav2_amcl process. This vulnerability is triggered via sending a request to change dynamic parameters.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38910">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-37863 – Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37863</guid>
    <pubDate>Thu, 05 Dec 2024 23:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-37863</strong></p>
  <p>Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37862 – Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 na...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37862</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37862</guid>
    <pubDate>Thu, 05 Dec 2024 23:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37862</strong></p>
  <p>Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_planner process.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37862">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-37861 – Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were di...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37861</guid>
    <pubDate>Thu, 05 Dec 2024 23:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-37861</strong></p>
  <p>Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_amcl process. This vulnerability is triggered via sending a crafted .yaml file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-37860 – Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37860</guid>
    <pubDate>Thu, 05 Dec 2024 23:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-37860</strong></p>
  <p>Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_amcl process</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-30964 – Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30964</guid>
    <pubDate>Thu, 05 Dec 2024 23:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-30964</strong></p>
  <p>Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the initial_pose_sub thread created by nav2_bt_navigator</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-30963 – Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30963</guid>
    <pubDate>Thu, 05 Dec 2024 23:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-30963</strong></p>
  <p>Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via a crafted script.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-30962 – Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30962</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30962</guid>
    <pubDate>Thu, 05 Dec 2024 23:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-30962</strong></p>
  <p>Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the nav2_amcl process</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30962">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-30961 – Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-30961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-30961</guid>
    <pubDate>Thu, 05 Dec 2024 23:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-30961</strong></p>
  <p>Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the error-thrown mechanism in nav2_bt_navigator.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-30961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-25199 – Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Op...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25199</guid>
    <pubDate>Tue, 20 Feb 2024 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-25199</strong></p>
  <p>Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-25198 – Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25198</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25198</guid>
    <pubDate>Tue, 20 Feb 2024 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-25198</strong></p>
  <p>Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25198">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-25197 – Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25197</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25197</guid>
    <pubDate>Tue, 20 Feb 2024 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-25197</strong></p>
  <p>Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25197">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-25196 – Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-25196</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-25196</guid>
    <pubDate>Tue, 20 Feb 2024 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-25196</strong></p>
  <p>Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-120</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-25196">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
