Release Info

Advisory: CLSA-2024:1733246466

OS: Ubuntu 18.04 ELS

Public date: 2024-12-03 12:21:08

Project: needrestart

Version: 3.1-1ubuntu0.1+tuxcare.els3

Errata link: https://errata.tuxcare.com/els_os/ubuntu18.04els/CLSA-2024-1733246466.html

Changelog

* SECURITY UPDATE: Race condition allows local attackers to execute arbitrary code as root - debian/patches/CVE-2024-48991.patch: Prevent race condition on /proc/$PID/exec evaluation by synchronizing $exe with the initial value from Proc:ProcessTable - CVE-2024-48991

Update

Update command: apt-get update apt-get --only-upgrade install needrestart*

Packages list

needrestart_3.1-1ubuntu0.1+tuxcare.els3_all.deb

CVEs

CVE-2024-48991
CVE-2024-11003
CVE-2024-48990