CVE-2024-42002 ROS 2 ros2topic 代码注入漏洞
影响本地用户可通过恶意表达式执行任意代码
CVE-2024-42002 是 ROS 2 命令行工具 ros2topic 中 hz 子命令的代码注入漏洞。该命令的 --filter 选项接收用户提供的 Python 表达式,未经净化直接传入 eval() 函数,导致本地攻击者可构造并执行任意代码。
影响范围
影响从 Crystal Clemmys 到 Lyrical Luth 及 Rolling Ridley 的所有 ROS 2 发行版,具体修复版本暂无公开信息。
漏洞详情
漏洞类型为代码注入(CWE-95,eval 注入)。ros2topic hz 用于统计话题发布频率,其 --filter 参数允许传入 Python 表达式用于过滤消息,但程序将该字符串直接交给 eval() 执行,未做任何校验或沙箱限制。攻击者只需在本地运行带恶意 --filter 表达式的命令,即可在目标进程权限下执行任意 Python 代码。
利用条件与风险
利用前提是攻击者能在本地执行 ros2topic 命令,属于本地权限提升/代码执行类风险;在共享开发环境或 CI 场景中,低权限用户可能借此获得更高权限。
修复建议
官方修复方案暂无公开信息,建议关注 ROS 2 官方安全公告并升级到已修复版本;临时缓解措施为避免使用不可信的 --filter 表达式,或对 ros2topic 命令的调用进行访问控制。
A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) ‘ros2topic’ command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the ‘hz’ verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the –filter option. This input is passed directly to the eval() function without sanitization, allowing a local user to craft and execute arbitrary code.