Fedora Account System
Red Hat Associate
Red Hat Customer
needrestart 0.8 through 3.5 before 3.6 is prone to local privilege escalation. Regexes to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate privileges when needrestart tries to detect if interpreters are using old source files. https://www.openwall.com/lists/oss-security/2022/05/17/9 https://github.com/liske/needrestart/releases/tag/v3.6 https://lists.debian.org/debian-security-announce/2022/msg00105.html https://github.com/liske/needrestart/commit/e6e58136e1e3c92296e2e810cb8372a5fe0dbd30 http://www.openwall.com/lists/oss-security/2022/05/17/9
Created needrestart tracking bugs for this issue: Affects: epel-7 [bug 2087660] Affects: epel-8 [bug 2087661] Affects: fedora-34 [bug 2087662] Affects: fedora-35 [bug 2087659]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.