CVE-2024-25199: Opennav NAV2

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Inappropriate pointer order of map_sub_ and map_free(map_) (amcl_node.cpp) in Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions leads to a use-after-free.

Affected products

  • Opennav NAV2: from 1.1.0, up to and including 1.1.17
  • Openrobotics Robot Operating System: version 2 only

Published 2024-02-20. Last modified 2026-06-17.