USN-7117-2: needrestart regression
USN-7117-1 fixed vulnerabilities in needrestart. The update introduced a regression in needrestart. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Qualys discovered that needrestart passed unsanitized data to a library (libmodule-scandeps-perl) which expects safe input. A local attacker could possibly use this issue to execute arbitrary code as root. (CVE-2024-11003) Qualys discovered that the library libmodule-scandeps-perl incorrectly parsed perl code. This could allow a local attacker to execute arbitrary shell commands. (CVE-2024-10224) Qualys discovered that needrestart incorrectly used the PYTHONPATH environment variable to spawn a new Python interpreter. A local attacker could possibly use this issue to execute arbitrary code as root. (CVE-2024-48990) Qualys discovered that needrestart incorrectly checked the path to the Python interpreter. A local attacker could possibly use this issue to win a race condition and execute arbitrary code as root. (CVE-2024-48991) Qualys discovered that needrestart incorrectly used the RUBYLIB environment variable to spawn a new Ruby interpreter. A local attacker could possibly use this issue to execute arbitrary code as root. (CVE-2024-48992)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7117-2?
USN-7117-2 addresses a regression introduced in needrestart, but does not specify a severity level.
How do I fix USN-7117-2?
To fix USN-7117-2, update the needrestart package to the latest version provided by Ubuntu.
What Ubuntu versions are affected by USN-7117-2?
USN-7117-2 affects Ubuntu versions 24.10, 24.04, 22.04, 20.04, 18.04, and 16.04.
What packages are involved in USN-7117-2?
USN-7117-2 involves the needrestart package with specific versions listed in the advisory.
What was the issue fixed in USN-7117-2?
USN-7117-2 fixed a regression in needrestart that resulted from a prior update.