CVE-2024-48992: High severity debian/needrestart vulnerability
Last updated 20 November 2024
Other sources
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.
— NVD
This CVE was automatically created from a reference found in an email or other text. If you are reading this, then this CVE entry is probably erroneous, since this text should be replaced by the official CVE description automatically.
— Launchpad
Affected Software
Remediation
Mitigation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48992?
CVE-2024-48992 has been classified as a high-severity vulnerability due to the potential for local attackers to execute arbitrary code as root.
How do I fix CVE-2024-48992?
To fix CVE-2024-48992, upgrade needrestart to version 3.8 or later.
What versions of needrestart are affected by CVE-2024-48992?
CVE-2024-48992 affects needrestart versions prior to 3.8, specifically versions 3.5-4+deb11u4, 3.6-4+deb12u2, and 3.7-3.1.
Can CVE-2024-48992 be exploited remotely?
CVE-2024-48992 cannot be exploited remotely as it requires local access to the system.
What impact does CVE-2024-48992 have on systems?
CVE-2024-48992 allows local attackers to gain root privileges, potentially leading to full system compromise.