CVE Vulnerabilities

CVE-2024-41648

Improper Preservation of Permissions

Published: Dec 06, 2024 | Modified: Dec 13, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via a crafted script to the nav2_regulated_pure_pursuit_controller.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

Name Vendor Start Version End Version
Robot_operating_system Openrobotics 2-humble (including) 2-humble (including)
Robot_operating_system Openrobotics 2-iron (including) 2-iron (including)

References