
Technical analysis and proof-of-concept for CVE-2024-48990, a privilege escalation vulnerability in needrestart allowing local attackers to execute arbitrary code as root via PYTHONPATH manipulation.
To determine whether a Python process (a process that is running the Python interpreter) needs to be restarted, needrestart extracts the PYTHONPATH environment variable from this process's /proc/pid/environ (at line 193), sets this environment variable if it exists (at line 196), and executes Python ("$ptable->{exec}" at line 203) with a "-" argument to read a short, hard-coded script from stdin (at line 204):
Unfortunately, if a Python process belongs to a local attacker, then needrestart executes Python (at line 203) with an attacker-controlled PYTHONPATH environment variable, which allows the attacker to execute arbitrary code as root (even though needrestart's hard-coded Python script at line 204 is not attacker-controlled at all). This is CVE-2024-48990.