Back to search
CVE-2022-30688
Published: May 17, 2022
Modified: Nov 3, 2025
PUBLISHED
Description
needrestart 0.8 through 3.5 before 3.6 is prone to local privilege escalation. Regexes to detect the Perl, Python, and Ruby interpreters are not anchored, allowing a local user to escalate privileges when needrestart tries to detect if interpreters are using old source files.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://github.com/liske/needrestart/releases/tag/v3.6
x_refsource_MISC
https://www.openwall.com/lists/oss-security/2022/05/17/9
x_refsource_MISC
[oss-security] 20220517 CVE-2022-30688: needrestart 0.8+ local privilege escalation
mailing-list
x_refsource_MLIST
DSA-5137
vendor-advisory
x_refsource_DEBIAN
[debian-lts-announce] 20220518 [SECURITY] [DLA 3013-1] needrestart security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now