CVE-2024-42002

Summary

A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the –filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.

Affected Software

VendorProductVersion RangeStatus
Open Source Robotics FoundationRobot Operating System 2 (ROS 2)Rolling Ridleyaffected
Open Source Robotics FoundationRobot Operating System 2 (ROS 2)Lyrical Luthaffected
Open Source Robotics FoundationRobot Operating System 2 (ROS 2)Kilted Kaijuaffected
Open Source Robotics FoundationRobot Operating System 2 (ROS 2)Jazzy Jaliscoaffected
Open Source Robotics FoundationRobot Operating System 2 (ROS 2)Iron Irwiniaffected
Open Source Robotics FoundationRobot Operating System 2 (ROS 2)Humble Hawksbillaffected
Open Source Robotics FoundationRobot Operating System 2 (ROS 2)Galactic Geocheloneaffected
Open Source Robotics FoundationRobot Operating System 2 (ROS 2)Foxy Fitzroyaffected
Open Source Robotics FoundationRobot Operating System 2 (ROS 2)Eloquent Elusoraffected
Open Source Robotics FoundationRobot Operating System 2 (ROS 2)Dashing Diademataaffected
Open Source Robotics FoundationRobot Operating System 2 (ROS 2)Crystal Clemmysaffected

Weaknesses

  • CWE-95: CWE-95 Improper neutralization of directives in dynamically evaluated code ('eval injection')
  • CWE-94: CWE-94 Improper Control of Generation of Code ('Code Injection')

Workarounds

Do not pass untrusted or unreviewed input to the –filter option of 'ros2 topic hz'.

References