CVE-2024-25197: Opennav NAV2
Medium severity, CVSS 6.5. EPSS: 0.7% chance of exploitation in the next 30 days.
Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp.
Affected products
- Opennav NAV2: from 1.1.0, up to and including 1.1.17
- Openrobotics Robot Operating System: version 2 only
Published 2024-02-20. Last modified 2026-06-17.