Code Injection in needrestart - CVE-2024-48992

 

Code Injection in needrestart - CVE-2024-48992

Published: November 27, 2024


Vulnerability identifier: #VU100984
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-48992
CWE-ID: CWE-94
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insecure handling of environment variables. A local user can trick the application into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable and execute arbitrary code on the system as root.

Affected software

needrestart
Debian Linux
Fedora
Ubuntu
needrestart (Ubuntu package)
needrestart (Debian package)
needrestart
OpenManage Network Integration (OMNI)

How to mitigate CVE-2024-48992

Install updates from vendor's website.

needrestart - update to 3.8
needrestart (Ubuntu package) - addressed in versions Ubuntu Pro, 3.5-5ubuntu2.3, 3.5-5ubuntu2.4, 3.6-7ubuntu4.4, 3.6-7ubuntu4.5, 3.6-8ubuntu4.3, 3.6-8ubuntu4.4
needrestart (Debian package) - update to 3.6-4+deb12u2
OpenManage Network Integration (OMNI) - update to 3.7
needrestart - addressed in versions 3.8-1.el8, 3.8-1.el9, 3.8-1.fc39, 3.8-1.fc40, 3.8-1.fc41

External References

Related Security Bulletins