vulnerability
Ubuntu: (Multiple Advisories) (CVE-2024-48990): needrestart and Module::ScanDeps vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:L/AC:L/Au:S/C:C/I:C/A:C) | Nov 19, 2024 | Nov 20, 2024 | Apr 16, 2026 |
Severity
7
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
Nov 19, 2024
Added
Nov 20, 2024
Modified
Apr 16, 2026
Description
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.
Solutions
ubuntu-pro-upgrade-libmodule-scandeps-perlubuntu-pro-upgrade-needrestartubuntu-upgrade-libmodule-scandeps-perlubuntu-upgrade-needrestart
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.