CVE-2024-48991Race Condition in Needrestart

CWE-362Race Condition15 documents7 sources
Severity
7.8HIGHNVD
EPSS
0.2%
top 59.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 19
Latest updateDec 5

Description

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreter (instead of the system's real Python interpreter). The initial security fix (6ce6136) introduced a regression which was subsequently resolved (42af5d3).

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

debiandebian/needrestart< needrestart 3.6-4+deb12u2 (bookworm)
CVEListV5needrestart/needrestart< 3.8
Debianneedrestart/needrestart< 3.5-4+deb11u4+3
Ubuntuneedrestart/needrestart< 3.5-5ubuntu2.3+14

Patches

🔴Vulnerability Details

5
OSV
needrestart regression2024-12-05
OSV
needrestart regression2024-11-26
GHSA
GHSA-4696-66c4-2gvx: Qualys discovered that needrestart, before version 32024-11-19
OSV
Several security issues were fixed in needrestart and Module::ScanDeps2024-11-19
OSV
CVE-2024-48991: Qualys discovered that needrestart, before version 32024-11-19

📋Vendor Advisories

4
Ubuntu
needrestart regression2024-12-05
Ubuntu
needrestart regression2024-11-26
Ubuntu
needrestart and Module::ScanDeps vulnerabilities2024-11-19
Debian
CVE-2024-48991: needrestart - Qualys discovered that needrestart, before version 3.8, allows local attackers t...2024

🕵️Threat Intelligence

5
Qualys
Mitigate High-Risk Vulnerabilities Using TruRisk | Qualys2024-12-04
Qualys
Proactively Managing High-Risk Vulnerabilities with TruRisk Mitigate™2024-12-04
Bleepingcomputer
Ubuntu Linux impacted by decade-old &#039;needrestart&#039; flaw that gives root2024-11-20
Qualys
Qualys TRU Uncovers Five Local Privilege Escalation Vulnerabilities in needrestart2024-11-19
Qualys
Qualys TRU Uncovers 5 Local Privilege Escalation Flaws | Qualys2024-11-19
CVE-2024-48991 — Race Condition in Needrestart | cvebase