DEBIAN-CVE-2024-41921

Source
https://security-tracker.debian.org/tracker/CVE-2024-41921
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-41921.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2024-41921
Upstream
Published
2025-07-17T20:15:27Z
Modified
2026-09-15T09:03:08Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

A code injection vulnerability has been discovered in the Robot Operating System (ROS) 'rostopic' command-line tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability lies in the 'echo' verb, which allows a user to introspect a ROS topic and accepts a user-provided Python expression via the --filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.

References

Affected packages

Debian:12 / ros-ros-comm

Package

Name
ros-ros-comm
Purl
pkg:deb/debian/ros-ros-comm?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.15.15+ds-2
1.16.0+ds-1
1.16.0+ds-2
1.16.0+ds-3
1.16.0+ds-3.1~exp1
1.16.0+ds-3.1
1.16.0+ds-4
1.16.0+ds-5
1.16.0+ds-6
1.17.0+ds-1
1.17.0+ds-2
1.17.4+ds-1
1.17.4+ds-2
1.17.4+ds-3
1.17.4+ds-4

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-41921.json"

Debian:13 / ros-ros-comm

Package

Name
ros-ros-comm
Purl
pkg:deb/debian/ros-ros-comm?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.17.0+ds-2
1.17.4+ds-1
1.17.4+ds-2
1.17.4+ds-3
1.17.4+ds-4

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-41921.json"

Debian:14 / ros-ros-comm

Package

Name
ros-ros-comm
Purl
pkg:deb/debian/ros-ros-comm?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.17.0+ds-2
1.17.4+ds-1
1.17.4+ds-2
1.17.4+ds-3
1.17.4+ds-4

Ecosystem specific

{
    "urgency":  "unimportant"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2024-41921.json"