Impact
The vulnerability resides in the ZJU-FAST-Lab EGO-Planner‑v2 project, specifically within the EGOReplanFSM::checkCollisionCallback function. A flaw in this callback permits an attacker to trigger a denial of service, causing the planner service to crash or become unresponsive. The impact is a disruption of the vehicle’s planning subsystem, potentially leading to loss of control or a system halt.
Affected Systems
All versions of ZJU-FAST-Lab EGO-Planner‑v2 up to commit 5c99a95880401e2599638d567abc0e240396cb42 are affected. Users who have not applied newer commits or patches are exposed to this denial‑of‑service condition.
Risk and Exploitability
No CVSS score is provided, and the EPSS score is unavailable, so the quantitative risk is uncertain. The vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. Nonetheless, the DoS effect could be critical in autonomous driving scenarios if the attacker can interact with the planner, possibly via a local network or by sending specially crafted inputs that invoke the checkCollisionCallback.
OpenCVE Enrichment