Input validation error in needrestart - CVE-2022-30688

 

Input validation error in needrestart - CVE-2022-30688

Published: May 18, 2022


Vulnerability identifier: #VU63356
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-30688
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code with elevated privileges.

The vulnerability exists due to application uses incorrect regexes to detect Perl, Python, and Ruby interpreters. A local user can pass specially crafted data to the application and execute arbitrary code with elevated privileges.


Affected software

needrestart
Fedora
Ubuntu
needrestart (Ubuntu package)
needrestart (Debian package)
needrestart

How to mitigate CVE-2022-30688

Install updates from vendor's website.

needrestart - update to 3.6
needrestart (Ubuntu package) - addressed in versions 3.1-1ubuntu0.1, 3.4-6ubuntu0.1, 3.5-4ubuntu2.1, 3.5-5ubuntu2.1
needrestart (Debian package) - addressed in versions 3.4-5+deb10u1, 3.5-4+deb11u1
needrestart - addressed in versions 3.6-3.el7, 3.6-3.el8

External References

Related Security Bulletins