vulnerability

Ubuntu: (Multiple Advisories) (CVE-2024-48990): needrestart and Module::ScanDeps vulnerabilities

Severity
7
CVSS
(AV:L/AC:L/Au:S/C:C/I:C/A:C)
Published
Nov 19, 2024
Added
Nov 20, 2024
Modified
Apr 16, 2026

Description

Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by tricking needrestart into running the Python interpreter with an attacker-controlled PYTHONPATH environment variable.

Solutions

ubuntu-pro-upgrade-libmodule-scandeps-perlubuntu-pro-upgrade-needrestartubuntu-upgrade-libmodule-scandeps-perlubuntu-upgrade-needrestart
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.