Description Needrestart使用PYTHONPATH环境变量执行Python解释器,如果本地攻击者控制该变量,可以通过植入恶意共享库,在Python初始化期间以root身份执行任意代码。
References https://nvd.nist.gov/vuln/detail/CVE-2024-48990 https://www.qualys.com/needrestart https://www.qualys.com/2024/11/19/needrestart/needrestart.txt https://ubuntu.com/blog/needrestart-local-privilege-escalation https://thehackernews.com/2024/11/decades-old-security-vulnerabilities.html https://github.com/liske/needrestart/commit/fcc9a4401392231bef4ef5ed026a0d7a275149ab https://github.com/czeti/CVE-2024-48990_needrestart https://medium.com/@allypetitt/rediscovering-cve-2024-48990-and-crafting-my-own-exploit-ce13829f5e80 https://github.com/pentestfunctions/CVE-2024-48990-PoC-Testing
Related VulnerabilitiesLinux内核RDS零拷贝与io_uring组合本地提权漏洞(PinTheft)Linux Kernel Fragnesia 本地权限提升漏洞(CVE-2026-46300)Linux Dirty Frag 本地提权漏洞Linux Kernel "Copy Fail" 本地权限提升漏洞(CVE-2026-31431)Linux ABRT 需授权 命令注入漏洞 可导致权限提升PoCCVE-2025-13315: Twonky Server 8.5.2 on Linux and Windows - Log File Exposure(CVE-2023-53408) Linux内核trace/blktrace内存泄漏漏洞(CVE-2023-53409)Linux内核debugfs_lookup()内存泄漏漏洞(CVE-2023-53418) Linux内核USB gadget lpc32xx_udc内存泄漏漏洞(CVE-2023-53416) Linux内核USB isp1362驱动内存泄漏漏洞(CVE-2023-53413)Linux内核USB驱动isp116x内存泄漏漏洞(CVE-2023-53410) Linux内核USB ULPI内存泄漏漏洞