Security updates were released for the Linux utility needrestart to fix five local privilege escalation vulnerabilities — CVE-2024-48990, CVE-2024-48991, CVE-2024-48992, CVE-2024-10224, and CVE-2024-11003 — that can let an authenticated local attacker execute code as root and take full control of affected systems. The bugs affect needrestart versions earlier than 3.8 and were disclosed by Qualys, with advisories warning that the package is installed by default on Ubuntu Server beginning with version 21.04.
The vulnerabilities include insufficient validation of the PYTHONPATH and RUBYLIB environment variables, a race condition involving crafted files, and improper input validation in the Perl library Modules::ScanDeps. Administrators were urged to upgrade to needrestart 3.8 immediately; where patching is not yet possible, guidance recommends disabling interpreter scanning in /etc/needrestart/needrestart.conf by setting:
$nrconf{interpscan} = 0;

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Splunk published a TTP detection analytic, "Linux Possible Privilege Escalation via PYTHONPATH," to identify creation of rogue importlib/__init__.so files outside standard library paths. The write-up explicitly cites exploitation of needrestart flaw CVE-2024-48990 as an example of how attackers can gain elevated code execution.
Security updates were released to fix the five needrestart privilege escalation vulnerabilities, and administrators were advised to upgrade to version 3.8. As a workaround where patching is not possible, interpreter scanning can be disabled via the needrestart configuration.
Qualys published details of five local privilege escalation vulnerabilities in the Linux utility needrestart: CVE-2024-48990, CVE-2024-48991, CVE-2024-48992, CVE-2024-10224, and CVE-2024-11003. The issues affect versions earlier than 3.8 and can allow a local authenticated attacker to gain root-level code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourcecsirt.sk
Open sourcequalys.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.