CVE-2024-48990

NameCVE-2024-48990
DescriptionQualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3957-1, DSA-5815-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
needrestart (PTS)bullseye3.5-4+deb11u3vulnerable
bullseye (security)3.5-4+deb11u4fixed
bookworm3.6-4+deb12u1vulnerable
bookworm (security)3.6-4+deb12u2fixed
trixie3.7-3vulnerable
sid3.7-3.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
needrestartsourcebullseye3.5-4+deb11u4DLA-3957-1
needrestartsourcebookworm3.6-4+deb12u2DSA-5815-1
needrestartsource(unstable)3.7-3.1

Notes

https://www.qualys.com/2024/11/19/needrestart/needrestart.txt
Fixed by: https://github.com/liske/needrestart/commit/fcc9a4401392231bef4ef5ed026a0d7a275149ab (v3.8)

Search for package or bug name: Reporting problems