Ubuntu alert USN-7117-2 (needrestart)
| From: | Sudhakar Verma <sudhakar.verma@canonical.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-7117-2] needrestart regression | |
| Date: | Tue, 26 Nov 2024 16:37:24 +0530 | |
| Message-ID: | <98f20290-a913-4e12-bbb9-a58343bebd6e@canonical.com> |
========================================================================== Ubuntu Security Notice USN-7117-2 November 26, 2024 needrestart regression ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: USN-7117-1 caused some regression in needrestart. Software Description: - needrestart: check which daemons need to be restarted after library upgrades Details: USN-7117-1 fixed vulnerabilities in needrestart. The update introduced a regression in needrestart. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Qualys discovered that needrestart passed unsanitized data to a library (libmodule-scandeps-perl) which expects safe input. A local attacker could possibly use this issue to execute arbitrary code as root. (CVE-2024-11003) Qualys discovered that the library libmodule-scandeps-perl incorrectly parsed perl code. This could allow a local attacker to execute arbitrary shell commands. (CVE-2024-10224) Qualys discovered that needrestart incorrectly used the PYTHONPATH environment variable to spawn a new Python interpreter. A local attacker could possibly use this issue to execute arbitrary code as root. (CVE-2024-48990) Qualys discovered that needrestart incorrectly checked the path to the Python interpreter. A local attacker could possibly use this issue to win a race condition and execute arbitrary code as root. (CVE-2024-48991) Qualys discovered that needrestart incorrectly used the RUBYLIB environment variable to spawn a new Ruby interpreter. A local attacker could possibly use this issue to execute arbitrary code as root. (CVE-2024-48992) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 needrestart 3.6-8ubuntu4.3 Ubuntu 24.04 LTS needrestart 3.6-7ubuntu4.4 Ubuntu 22.04 LTS needrestart 3.5-5ubuntu2.3 Ubuntu 20.04 LTS needrestart 3.4-6ubuntu0.1+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS needrestart 3.1-1ubuntu0.1+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS needrestart 2.6-1ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7117-2 https://ubuntu.com/security/notices/USN-7117-1 https://launchpad.net/bugs/2089193 Package Information: https://launchpad.net/ubuntu/+source/needrestart/3.6-8ubu... https://launchpad.net/ubuntu/+source/needrestart/3.6-7ubu... https://launchpad.net/ubuntu/+source/needrestart/3.5-5ubu...
Attachment: OpenPGP_signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- wsF5BAABCAAjFiEEcfvxe+flLQwqLJFE8LYUYLBMS1YFAmdFq+wFAwAAAAAACgkQ8LYUYLBMS1ZB HRAAyRz+/+IL6QvAroZ0XRsZwRPyxafhWnv/Vc9aWhJuaMGeA4ecyUqFYTFL0BAvmWzkTzxd9F5P WpbQWk1X7d06GIjIrhkpYWm/79fNTQaG8VaoNfLdxhzZckM62f41tRFZ/yh55kDtpANcJn+p/eNO 4CnHG08JAKi+QUHCOFy9Fuqy9DgCMlbRxFivaj9T0Kk5UJb2N77qYE3SrZLT7BnsCnA1pUOkzB0W lu5GFSqU0yUGS771Bt2QLI3afKaMtOsk4rLEwwJ1wGwrnKSfzqicfmFb26mJM3cGNgCjjHHBSavG ah7i0A/aIf/xuqX+McciLdMtclUqtBPoa0kVnXcq45VSn+RJ/XWS0fXS4IFK9JuIpitWZjXIUJLN cHGGw7uG3haTAVdLO+YHVXXnDLC3P4PApc9KvhaIe0Fkb4dnA1ffD32a/jWjMTpO7SetHNORE21b wrt7S9BtrHYrz4Cp8QY6nX2lCi0AOi/y701XqAUDwe3MrRPc847Na0yR1im3I7u1fUoRY+56ckbs GcTA7Xs4wCKs1Rr98PZaQn5xjId24k5Wk7Rcit/1kCs/Yb2x1+eBzM5yGL8cgUHNJNVqoa1mefw9 Ko6/D2c3vrJ0UM14DnjqIFW4t9JFJyUrzZL//pyHzZ2u3YKaj0O72pEVykFtLexrVQxDzlp9b04j Xe4= =lzls -----END PGP SIGNATURE-----
Attachment: None (type=text/plain)
