CVE-2024-48990 is an uncontrolled Python module search-path vulnerability in needrestart before version 3.8. Insufficient validation of the PYTHONPATH environment variable allows a local attacker to cause needrestart, executing with root privileges, to invoke the Python interpreter with an attacker-controlled module search path. A malicious replacement module can then be loaded in place of the legitimate module, resulting in arbitrary code execution as root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
20 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small local privilege-escalation proof-of-concept for CVE-2024-48990 affecting needrestart on Linux. It contains two files: a README in Spanish explaining the technique and a shell script snippet ('code to paste terminal') that performs the exploit steps. The exploit is not part of a larger framework. The core capability is local root escalation via PYTHONPATH hijacking. The script creates a fake Python package tree at /tmp/malicious/importlib and places a malicious importlib/__init__.py there. That payload checks whether it is running as root and, if so, copies /bin/bash to /tmp/poc and sets the SUID bit (chmod 4755). A benign Python script e.py is then launched with PYTHONPATH pointing to /tmp/malicious so that needrestart will later inspect a running Python process carrying the attacker-controlled environment. When needrestart is executed with elevated privileges, it allegedly inspects the running Python process and spawns/interacts with Python in a way that inherits the malicious PYTHONPATH. This causes the root-owned Python context to import the attacker-controlled importlib package, executing the payload and creating the SUID shell. The final step runs /tmp/poc -p to preserve privileges and provide a root shell. Repository structure is minimal and operational: the README documents the attack flow, while the shell snippet is the practical entry point. There are no network callbacks, C2 endpoints, or remote targets; all observables are local filesystem paths and the privileged binary /usr/sbin/needrestart. The exploit is clearly offensive code rather than a detector, and its payload is hardcoded but functional, making it best classified as OPERATIONAL.
Repository purpose: a local privilege-escalation exploit targeting CVE-2024-48990 in needrestart (claimed vulnerable version 3.7-3 on Debian-based systems). The core idea is to plant an attacker-controlled Python module path so that when needrestart (running as root) performs Python imports, it loads a malicious `importlib` package from `/tmp/attacker/importlib/`, whose `__init__.so` executes embedded x86_64 shellcode. Structure and flow: - `src/main.asm`: NASM assembly that defines a shared-object initializer (`_init`) which immediately executes embedded shellcode bytes. The shellcode appears to perform syscalls and then `execve` (syscall 59 / 0x3b) with constructed arguments; the trailing byte strings look obfuscated/encoded, consistent with a compact payload that likely drops or triggers creation of `/tmp/poc`. - `makefile`: Builds the shared object by assembling `src/main.asm` and linking it as a shared library with `_init` entrypoint, outputting to `/tmp/attacker/importlib/__init__.so`. This placement is intentional to masquerade as the `importlib` module/package. - `src/listener.sh`: Creates `/tmp/attacker/subprocess.py` and runs it with `PYTHONPATH` set to `/tmp/attacker`. The Python script loops importing `importlib` (to trigger loading the malicious module) and checks for `/tmp/poc`. When `/tmp/poc` exists, it prints `Root obtained!, clear traces ...` and runs `sudo /tmp/poc -p`. - `README.md`: Provides manual trigger instructions: run `make`, then wait for/trigger `sudo needrestart -r a` so needrestart loads the malicious module and escalates. Exploit capabilities: - Establishes a malicious Python import path and a trojaned `importlib` module implemented as a shared object. - Executes native shellcode in the context of the importing process (intended: root-run needrestart), enabling arbitrary code execution and privilege escalation. - Includes a basic local “listener”/monitor loop to detect success via the presence of `/tmp/poc` and then attempt a follow-on privileged execution. No network C2/endpoints are present; the exploit is purely local and relies on filesystem paths under `/tmp` and a privileged needrestart invocation.
Repository contains a local privilege escalation exploit for CVE-2024-48990 affecting needrestart < 3.8 on Debian/Ubuntu. Structure is minimal: (1) README.md describing the vulnerability, affected versions, usage, detection, and mitigation; (2) exploit.sh, a Bash exploit driver that builds and deploys a Python import-hijack payload. Core technique: needrestart scans running processes and, for Python processes, re-invokes the interpreter as root while inheriting the full environment from /proc/<pid>/environ. The exploit creates a temporary directory under /tmp/.nr_XXXXXX containing a fake Python package `importlib` with a malicious `__init__.py`. It then spawns a long-running decoy python3 process with PYTHONPATH pointing to that directory. When needrestart runs (manually via sudo /usr/sbin/needrestart or automatically via apt hooks), it discovers the decoy process and re-invokes python as root, causing the attacker’s importlib to be imported and executed. Capabilities/payloads: By default, the malicious module runs `cp /bin/bash /var/tmp/.rootshell && chmod 4755 /var/tmp/.rootshell`, creating a SUID-root shell in /var/tmp (chosen to avoid /tmp nosuid). The script then waits up to a configurable timeout (-w, default 300s) for the SUID binary to appear and executes `/var/tmp/.rootshell -p` to obtain a root shell. Alternatively, the operator can supply an arbitrary root command via -c. There is an optional trigger mode (-t) that attempts to run `sudo apt install -y --reinstall coreutils` to invoke needrestart automatically (requires passwordless sudo for apt). Operational details: exploit.sh includes a version check using dpkg-query and a simple Python comparison to warn if needrestart is >= 3.8, sets traps to clean up the temporary directory unless -n is used, and attempts to reduce visible impact by removing the fake importlib path from sys.path and deleting importlib-related entries from sys.modules after executing the payload to avoid crashing needrestart.
This repository provides a local privilege escalation exploit for CVE-2024-48990, targeting the 'needrestart' utility on Linux systems prior to version 3.8. The exploit consists of three main files: a C shared object (exploit.c), a Bash script (runner.sh), and a Python trigger script (trigger.py). The attack requires the victim to download and execute a script (runner.sh) from the attacker's web server. This script downloads a malicious shared object and a Python script, sets up the environment, and runs the trigger script with a manipulated PYTHONPATH. The shared object, when loaded by Python running as root (via needrestart), creates a setuid root shell at /tmp/shell and modifies /etc/sudoers to allow passwordless sudo execution of this shell. The exploit is operational and demonstrates a full privilege escalation chain, but requires some manual setup and user interaction. The main attack vector is local, exploiting the way needrestart handles the PYTHONPATH environment variable.
This repository contains a proof-of-concept exploit for CVE-2024-48990, a privilege escalation vulnerability in the 'needrestart' utility on Linux. The exploit consists of a Bash script ('exploit.sh') that sets up a malicious Python module in '/tmp', manipulates the PYTHONPATH, and runs 'needrestart' via sudo. If the exploit is successful, the malicious Python code is executed as root, establishing a reverse shell to an attacker-controlled IP and port (which must be set by the user). The repository also includes a README.md with usage instructions and context. The exploit is operational and provides a root shell if the target is vulnerable and properly configured.
This repository contains a local privilege escalation exploit for the 'needrestart' utility, targeting CVE-2024-48990. The exploit is implemented in a single Python script ('needrestart_privesc.py'), which abuses the '-c' configuration option of needrestart to execute arbitrary Perl code as root. The script writes a Perl payload to a temporary file ('/tmp/cmd.conf'), which, when executed by needrestart via sudo, copies /bin/bash to /tmp/bash and sets the SUID bit, creating a root shell. The script then spawns this shell for the attacker. The exploit does not require compilation or additional tools, only that the user can run needrestart via sudo. The repository also includes a README.md with detailed usage instructions and a LICENSE file. The main attack vector is local privilege escalation, and the main fingerprintable endpoints are the temporary files '/tmp/cmd.conf' and '/tmp/bash'.
This repository provides a proof-of-concept exploit for CVE-2024-48990, a local privilege escalation vulnerability in needrestart (before version 3.8). The exploit leverages the ability to control the PYTHONPATH environment variable, tricking needrestart into importing a malicious Python module as root. The main exploit logic is contained in 'poc.sh', which sets up a temporary directory, creates a malicious 'importlib' Python package, and waits for needrestart to execute Python with the attacker's PYTHONPATH. When triggered, the malicious module copies /bin/bash to /tmp/bash and sets the SUID bit, creating a root shell. The repository also includes 'loop.py' and 'privesc.py' as demonstration scripts, but the core exploit is in 'poc.sh'. The attack vector is local, requiring the attacker to have access to the system and the ability to influence needrestart's environment. The main fingerprintable endpoint is the creation of the SUID shell at /tmp/bash.
This repository provides a local privilege escalation exploit for CVE-2024-48990, targeting the 'needrestart' utility on Linux systems. The exploit consists of three files: a C source file (lib.c) for a malicious shared object, a Bash script (run.sh) to set up and trigger the exploit, and a README.md with usage instructions. The attack works by hijacking the PYTHONPATH to load a malicious importlib module (exp.so) when 'needrestart' scans a Python process. When loaded as root, the shared object copies /bin/sh to /tmp/poc, makes it SUID root, and adds a sudoers rule for persistence. The run.sh script creates a bait Python process and waits for the exploit to succeed. The exploit provides persistent root access via the SUID shell and sudoers modification. Key fingerprintable endpoints include /tmp/poc, /etc/sudoers, and the malicious shared object path.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-48990, a local privilege escalation vulnerability in needrestart versions prior to 3.8 on Linux. The exploit leverages the fact that needrestart, when running as root, can be tricked into loading a malicious Python library via a manipulated PYTHONPATH environment variable. The repository contains three files: a README.md with detailed instructions and background, binary.sh which generates a C shared object payload that creates a setuid root shell and modifies /etc/sudoers, and runner.sh which sets up the malicious directory structure, downloads the payload from an attacker-controlled HTTP server, and runs a Python script to trigger the exploit. The main attack vector is local, requiring the attacker to execute code on the target system. The exploit results in a root shell at /tmp/poc, which is also added to sudoers for passwordless execution. The repository is well-structured for operational use, with clear instructions and automation scripts for both payload creation and exploitation.
This repository provides a working proof-of-concept exploit for CVE-2024-48990, a local privilege escalation vulnerability in the 'needrestart' utility (versions prior to 3.8) on Linux systems. The exploit consists of a Bash script ('exploit.sh') that sets up a malicious Python module and a lure process. When 'needrestart' is triggered (typically during package installation), it scans running processes and, if it finds a Python process, it trusts the PYTHONPATH environment variable. The exploit leverages this by running a Python process with a crafted PYTHONPATH pointing to a directory containing a malicious 'importlib' module. When 'needrestart' (running as root) imports this module, the payload executes and creates a SUID root shell at a known location ('poc/pwned'). The attacker can then use this shell to gain root privileges. The repository is structured with a README.md explaining the vulnerability and usage, and a single exploit script that automates the attack. No network endpoints are involved; all actions are local to the target system.
This repository provides a local privilege escalation exploit for CVE-2024-48990, targeting needrestart versions prior to 3.8 on Linux. The exploit leverages the fact that needrestart, when run as root, can be tricked into executing Python with a malicious PYTHONPATH, causing it to load a shared object under attacker control. The repository contains: - A C source file (exploit.c) that, when compiled as a shared object (__init__.so), creates a SUID root shell at /tmp/rootbash when loaded as root. - Bash scripts (compile.sh, setup_exploit.sh) to compile the payload and set up the exploit environment, including downloading the malicious shared object and preparing a Python script (e.py) that waits for the root shell to appear. - A Python script (trigger.py) that can be used to spawn a process with a crafted PYTHONPATH to trigger the vulnerability. - The README.md provides detailed usage instructions, including how to serve the payload to the target and how to trigger the exploit using needrestart. The exploit is operational and provides a working SUID root shell if the target is vulnerable. The main attack vector is local, requiring the attacker to execute code on the target system. The exploit uses several fingerprintable file paths in /tmp and downloads the payload via HTTP from an attacker-controlled server.
This repository contains a local privilege escalation exploit for CVE-2024-48990, targeting needrestart version 3.7 on Linux systems. The exploit is implemented in a single Python script (exploit.py), which automates the attack process. The script compiles a malicious shared object (__init__.so) in C, starts a local HTTP server to serve this payload, and connects to the target via SSH. It uploads and executes a bash script on the target, which sets up a malicious PYTHONPATH and runs a bait Python process to trigger the import of the attacker's shared object. When needrestart is run with sudo, it loads the malicious module as root, which creates a SUID root shell at /tmp/poc. The exploit requires the attacker to have SSH access to the target and the target to have sudo NOPASSWD rights for needrestart. The repository is well-structured, with clear separation between the exploit code, documentation, and license. The main entry point is exploit.py, and the exploit is operational, providing a working root shell if successful.
This repository contains a single Metasploit module: 'Ubuntu needrestart Privilege Escalation' (modules/exploits/linux/local/ubuntu_needrestart_lpe.rb). The module exploits CVE-2024-48990, a local privilege escalation vulnerability in the 'needrestart' utility on Ubuntu Linux. The exploit works by uploading a payload executable and a C stub (to set SUID) into a writable directory (default: /tmp), and a Python script that manipulates the PYTHONPATH environment variable to trick needrestart into executing the attacker's code as root. The module checks for vulnerable versions of needrestart on Ubuntu (with specific version checks for 22.04 and others), but notes that exploitation does not work on Debian or Fedora. The exploit provides root privileges to the attacker by executing arbitrary code as root. The module is operational and requires a local session on the target. No network endpoints are involved; all actions are performed locally on the compromised system.
This repository provides a working privilege escalation exploit for CVE-2024-48990, targeting Needrestart 3.7-3 on Debian-based Linux systems. The exploit leverages improper input handling in Needrestart to execute a malicious shared object with root privileges. The repository contains three main code files: an assembly shellcode (src/main.asm) compiled into a shared object, a Bash script (src/listener.sh) that sets up a Python-based listener to monitor for successful exploitation, and a Makefile to automate the build and execution process. The exploit works by placing a malicious __init__.so in /tmp/attacker/importlib/, then waiting for an administrator to run 'sudo needrestart -r a', which loads the attacker's code and escalates privileges. The exploit is operational and provides root access if successful. Several fingerprintable file paths are used, notably under /tmp/attacker/. The exploit is not part of a framework and is a standalone operational privilege escalation tool.
This repository provides a local privilege escalation exploit for CVE-2024-48990, targeting needrestart version 3.7 on Linux systems. The exploit abuses the PYTHONPATH environment variable to load a malicious shared object (compiled from evil.c) when needrestart is run by a privileged user. The shared object copies /bin/sh to /tmp/nullbyte, remounts /tmp with the suid option, and sets /tmp/nullbyte as a SUID root shell. The Python script (get_root.py) automates the setup and monitors for the creation of /tmp/nullbyte, executing it to obtain a root shell. The bash script (sysadmin_F.sh) moves the exploit files to /tmp and sets up the environment for exploitation. The exploit requires the attacker to have the ability to place files in /tmp and set environment variables, and for a privileged user to run needrestart. The main fingerprintable endpoints are files in /tmp: /tmp/importlib, /tmp/importlib/__init__.so, /tmp/evil.c, and /tmp/nullbyte.
This repository contains an exploit for CVE-2024-48990. The exploit leverages Python's import system by providing a malicious 'importlib' module. When the PYTHONPATH environment variable is set to the attacker's directory and a privileged process (such as during 'sudo apt install') imports 'importlib', the attacker's code is executed. The payload in 'importlib/__init__.py' opens a reverse shell to 127.0.0.1:1337, granting a shell to the attacker. The 'main.py' file is a placeholder and does not contain exploit logic. The README provides usage instructions, and the LICENSE is MIT. The exploit is operational and requires local access and specific environmental manipulation to succeed.
This repository contains a local privilege escalation exploit targeting systems where the 'needrestart' utility is run as root, typically during package management operations (e.g., apt-get). The main exploit script, 'privesc.sh', automates the creation of a malicious shared object (.so) file and places it in a specially crafted directory ('importlib'). When the vulnerable process loads this .so file, it executes code that copies the system's bash binary to /tmp/ribbit and sets the SUID bit, making it a root shell. A Python script is also generated and run to monitor for the creation of /tmp/ribbit; once present, it executes the binary to provide a root shell to the attacker. The exploit is operational and demonstrates a working privilege escalation technique, but is not weaponized for mass exploitation. The repository is structured simply, with a single exploit script and a README explaining its use.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-48990, a privilege escalation vulnerability in the 'needrestart' package (version 3.7-3) on Linux systems. The exploit leverages improper handling of Python's path by 'needrestart' to load a malicious shared object. The repository contains three files: a detailed README.md with instructions and background, a runner.sh script that automates the exploit steps, and a placeholder images.md file. The runner.sh script creates a malicious C shared object that, when loaded with root privileges, creates a setuid root shell at /tmp/poc and adds a sudoers entry to allow passwordless execution of this shell. The exploit is local and requires the attacker to trigger 'needrestart' (e.g., via package installation). The PoC is intended for testing in controlled environments and demonstrates a clear path to privilege escalation on vulnerable systems.
This repository contains a local privilege escalation exploit for CVE-2024-48990, targeting needrestart versions less than 3.8 on Linux systems. The exploit consists of a single C source file ('exploit.c') that, when compiled as a shared object and loaded by a vulnerable needrestart process, executes a shell command to modify '/etc/passwd'. This command adds a new user '_daemon' with UID and GID 0 (root privileges) and a known password, effectively granting root access to the attacker. The README.md provides detailed exploitation steps, including how to set up the environment, trigger the vulnerable code path in needrestart, and place the malicious shared object in the correct directory. The exploit is operational and requires local access, but does not require user interaction once set up. Key fingerprintable endpoints include '/etc/passwd', the location for the malicious shared object ('/tmp/.X11-Unix/importlib/__init__.so'), and the needrestart configuration file. The repository is straightforward, with one exploit source file and a comprehensive README explaining the vulnerability and exploitation process.
This repository is a proof-of-concept exploit for CVE-2024-48990 in the 'needrestart' utility on Linux. The exploit consists of a C file ('lib.c') that is compiled into a malicious shared object and placed in a directory structure mimicking a Python library ('importlib'). The 'start.sh' script compiles this shared object and sets the PYTHONPATH so that when 'needrestart' is run as root, it loads the attacker's code. The C payload copies /bin/sh to /tmp/poc and sets the setuid bit, creating a root shell. The Python script ('e.py') waits for the shell to be created and then executes it, providing the attacker with root access. The exploit is local and requires the attacker to manipulate the environment such that their code is loaded by a privileged process. The main fingerprintable endpoint is the setuid shell at /tmp/poc. The repository is structured with a README, the exploit logic in C and Python, and a shell script to automate setup and execution.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability referenced in Gentoo GLSA-202608-22 affecting the Gentoo needrestart package; specific flaw details are not provided in the content.
A local privilege escalation vulnerability in NeedRestart that can be abused via PYTHONPATH manipulation to make a privileged NeedRestart process load a rogue Python module and execute code as root.
Local privilege escalation vulnerability in needrestart caused by insufficient validation of the PYTHONPATH environment variable, allowing an authenticated local attacker to execute malicious code as root.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.