Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2_controller process. This vulnerability is triggerd via sending a crafted .yaml file.
| Software | From | Fixed in |
|---|---|---|
| opennav / nav2 | 1.1.0 | 1.1.17.x |
| openrobotics / robot_operating_system | 2-humble | 2-humble.x |