USN-7117-3: needrestart regression
USN-7117-1 fixed vulnerabilities in needrestart. The update introduced a regression in needrestart. This update fixes the problem for LXC containers. We apologize for the inconvenience. Original advisory details: Qualys discovered that needrestart passed unsanitized data to a library (libmodule-scandeps-perl) which expects safe input. A local attacker could possibly use this issue to execute arbitrary code as root. (CVE-2024-11003) Qualys discovered that the library libmodule-scandeps-perl incorrectly parsed perl code. This could allow a local attacker to execute arbitrary shell commands. (CVE-2024-10224) Qualys discovered that needrestart incorrectly used the PYTHONPATH environment variable to spawn a new Python interpreter. A local attacker could possibly use this issue to execute arbitrary code as root. (CVE-2024-48990) Qualys discovered that needrestart incorrectly checked the path to the Python interpreter. A local attacker could possibly use this issue to win a race condition and execute arbitrary code as root. (CVE-2024-48991) Qualys discovered that needrestart incorrectly used the RUBYLIB environment variable to spawn a new Ruby interpreter. A local attacker could possibly use this issue to execute arbitrary code as root. (CVE-2024-48992)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7117-3?
The severity of USN-7117-3 is classified as a regression that affects LXC containers in the needrestart package.
How do I fix USN-7117-3?
To fix USN-7117-3, update the needrestart package to version 3.6-8ubuntu4.4 or the appropriate fixed version for your Ubuntu release.
What versions of Ubuntu are affected by USN-7117-3?
USN-7117-3 affects Ubuntu versions 24.10, 24.04, 22.04, 20.04, 18.04, and 16.04.
What package is impacted by USN-7117-3?
The impacted package by USN-7117-3 is needrestart.
What was the primary issue addressed by USN-7117-3?
USN-7117-3 addresses a regression introduced in needrestart that affected its functioning in LXC containers.