CVE-2024-25198: Opennav NAV2

Critical severity, CVSS 9.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Inappropriate pointer order of laser_scan_filter_.reset() and tf_listener_.reset() (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.

Affected products

  • Opennav NAV2: from 1.1.0, up to and including 1.1.17
  • Openrobotics Robot Operating System: version 2 only

Published 2024-02-20. Last modified 2026-06-17.