← Vulnerability feed

Vulnerability record · CVE-2024-25197 · published 20 February 2024

CVE-2024-25197: Opennav nav2 null pointer dereference vulnerability

Opennav · Nav2

Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp.

6.5 CVSS 3.1 Medium EPSS 0.68% · top 49.5% CWE-476 · NULL pointer dereference
6.5CVSS 3.1 base score
0.68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

Open Robotics Robotic Operating Sytstem 2 (ROS2) and Nav2 humble versions were discovered to contain a NULL pointer dereference via the isCurrent() function at /src/layered_costmap.cpp.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-25197 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-39780Openrobotics robot operating system improper input validation vulnerabilityA YAML deserialization vulnerability was found in the Robot Operating System (ROS) 'dynparam', a command-line tool for getting, setting, and deleting…EPSS 0.39%9.8CVE-2024-41649Openrobotics robot operating system vulnerabilityInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code…EPSS 0.70%9.8CVE-2024-41650Openrobotics robot operating system vulnerabilityInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code…EPSS 0.48%9.8CVE-2024-44852Openrobotics robot operating system vulnerabilityOpen Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a segmentation violation via the component theta_star::T…EPSS 0.60%9.8CVE-2024-38925Openrobotics robot operating system use after free vulnerabilityOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This …EPSS 0.59%9.8CVE-2024-38926Openrobotics robot operating system use after free vulnerabilityOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This …EPSS 0.59%9.8CVE-2024-38927Openrobotics robot operating system use after free vulnerabilityOpen Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This …EPSS 0.59%9.8CVE-2024-41644Openrobotics robot operating system vulnerabilityInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code…EPSS 0.70%

Source: NIST National Vulnerability Database (record CVE-2024-25197), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.