[ GLSA 202608-22 ] needrestart: Multiple vulnerabilities

[email protected]
Newsgroups gmane.linux.gentoo.announce
Message-ID <178755408002.1.15454976195977772519@f5bc8f6d682b>
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 202608-22
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                           https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

 Severity: High
    Title: needrestart: Multiple vulnerabilities
     Date: August 24, 2026
     Bugs: #944015
       ID: 202608-22

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been discovered in needrestart, the worst
of which allowing root privilege escalation.

Background
==========

needrestart is a tool to restart daemons after library updates.

Affected packages
=================

Package                Vulnerable    Unaffected
---------------------  ------------  ------------
app-admin/needrestart  < 3.8         >= 3.8

Description
===========

Multiple vulnerabilities have been discovered in needrestart. Please
review the CVE identifier referenced below for details.

Impact
======

An attacker could achieve root privilege escalation.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All needrestart users should upgrade to the latest version:

  # emerge --sync
  # emerge --ask --oneshot --verbose ">=app-admin/needrestart-3.8"

References
==========

[ 1 ] CVE-2024-11003
      https://nvd.nist.gov/vuln/detail/CVE-2024-11003
[ 2 ] CVE-2024-48990
      https://nvd.nist.gov/vuln/detail/CVE-2024-48990
[ 3 ] CVE-2024-48991
      https://nvd.nist.gov/vuln/detail/CVE-2024-48991
[ 4 ] CVE-2024-48992
      https://nvd.nist.gov/vuln/detail/CVE-2024-48992

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

 https://security.gentoo.org/glsa/202608-22

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
[email protected] or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2026 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5
signature.asc (application/pgp-signature, 870 B)
-----BEGIN PGP SIGNATURE-----

iQJPBAEBCAA5FiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmqL6R8bFIAAAAAABAAO
bWFudTIsMi41KzEuMTIsMiwyAAoJEBTEJDmlcvvZvHoQAKmduOVn9Vz9zkiPLae1
hvjJmFLVcNffmM5EsES4P31jOnQIE11bkyPYOtuS1NpemJdzJUO4Ix7iBSIWPOQE
DyVqlT4ynCSoG56lUvlcvAMdCkG81h/GW1uf1XP1VwwP+JGrPAJWao8RDhhmqygM
H1Njhv1GrxR42IoRkcCJQu9wjHCethxrqT5beuYXjN24PD6IIyLA90cjMXwpH1tk
bf6Fc5Ji4fGOeErkyETEN1/c1jkc6O7VF2e8pQcDpDHHJ0R3UGjCjP8NmVD2IHGh
+l1hMy28EbFuxs66d3ybACvSbYO3Y6BHReybRdNVTMcdneDfTxstJy195JcDDVso
3eKQXhlymx2gE4jgV5BJyu4Ikp788dq1xxWJ96C0dFKtG+khbK2kmo98Y5F94VUn
lr2pObWYSmBled0QUOT1HCLzOV+UBTkoHDUx6U/pYxA2T9trsG/NR4PObdntpB5N
TpSwjMYrCWiNKUcCj0wnC2gzmRl4BGzTe7JHHRBeklqGvgzTGOkmBn/JWNZuxswA
hOwJnCtsO7GgL15aoilwya70wOeFTWUOHOfwCPB3XyCbjiegWv+QYh6R1KWwyvon
eEN424Z+3AApaQwIEPlDyyzuNGLESCPupa6qjcNcopXJFukNyaoPf7CrRwCi1NUl
6uv05oanQ6XaDrBtC83HzH+l
=9r+y
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.