VulnerabilityModified
CVE-2024-48992
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.
HIGH 7.8EPSS 7.57%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Ruby interpreter with an attacker-controlled RUBYLIB environment variable.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 7.57% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-427
- Affected
- needrestart project/needrestart
- Source
- security@ubuntu.com
References
- https://github.com/liske/needrestart/commit/b5f25f6ec6e7dd0c5be249e4e45de4ee9ffe594fPatch
- https://www.cve.org/CVERecord?id=CVE-2024-48992VDB Entry
- https://www.qualys.com/2024/11/19/needrestart/needrestart.txtThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Nov/17
- https://lists.debian.org/debian-lts-announce/2024/11/msg00014.html
- https://www.openwall.com/lists/oss-security/2024/11/19/1Mailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.