CVE-2024-48991·Python vulnerability
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute arbitrary code as root by winning a race condition and tricking needrestart into running their own, fake Python interpreter (instead of the system's real Python interpreter). The initial security fix (6ce6136) introduced a regression which was subsequently resolved (42af5d3).
- Severity
- high
- Software
- Python
- Fixed in
- 3.8
- Published
- 2024-11-19
Affected versions
Until: 3.8
Fixed in: 3.8
How to fix this CVE
Update needrestart to version 3.8 or later to eliminate a local privilege escalation vulnerability that allows authenticated attackers to execute arbitrary code with root privileges. This vulnerability stems from a race condition in how needrestart spawns Python interpreters. Apply the patch immediately on all systems where needrestart is installed, particularly on multi-user or shared hosting environments.
sudo dnf update needrestartDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check the installed version of needrestart with: needrestart -v
- Step 2: Verify if needrestart is running as a service or scheduled task: systemctl status needrestart || crontab -l | grep needrestart
- Step 3: Review /var/log/auth.log (Debian/Ubuntu) or /var/log/secure (RHEL/CentOS) for suspicious sudo execution or unexpected Python process spawning from needrestart
- Step 4: Confirm the patch is applied by running needrestart -v again and verifying the version is 3.8 or higher
FAQ
What is CVE-2024-48991?
CVE-2024-48991 is a privilege escalation vulnerability in needrestart versions before 3.8 where local users can exploit a race condition to inject a malicious Python interpreter and gain root-level code execution. The vulnerability affects how needrestart locates and executes system Python binaries.
Is CVE-2024-48991 being actively exploited?
No, according to CISA's Known Exploited Vulnerabilities (KEV) catalog, CVE-2024-48991 is not currently being actively exploited in the wild, and no public proof-of-concept code is available.
What versions of needrestart are affected by CVE-2024-48991?
All versions of needrestart prior to version 3.8 are vulnerable. Version 3.8 and later include the security patch that closes the race condition.
How do I check if my server is vulnerable to CVE-2024-48991?
Run 'needrestart -v' to display the installed version. If the version is below 3.8, your system is vulnerable and requires immediate patching.
Does Defensia detect CVE-2024-48991?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If needrestart is installed on a monitored server, CVE-2024-48991 will appear in your dashboard with remediation steps.
Related Python CVEs
References
- https://github.com/liske/needrestart/commit/42af5d328901287a4f79d1f5861ac827a53fd56d
- https://github.com/liske/needrestart/commit/6ce6136cccc307c6b8a0f8cae12f9a22ac2aad59
- https://www.cve.org/CVERecord?id=CVE-2024-48991
- https://www.qualys.com/2024/11/19/needrestart/needrestart.txt
- http://seclists.org/fulldisclosure/2024/Nov/17
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2024-48991. Free for 1 server.
Get started free