needrestart: Multiple vulnerabilities — GLSA 202608-22

Multiple vulnerabilities have been discovered in needrestart, the worst of which allowing root privilege escalation.

Affected packages

app-admin/needrestart on all architectures
Affected versions < 3.8
Unaffected versions >= 3.8

Background

needrestart is a tool to restart daemons after library updates.

Description

Multiple vulnerabilities have been discovered in needrestart. Please review the CVE identifier referenced below for details.

Impact

An attacker could achieve root privilege escalation.

Workaround

There is no known workaround at this time.

Resolution

All needrestart users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=app-admin/needrestart-3.8"
 

References

Release date
August 24, 2026

Latest revision
August 24, 2026: 1

Severity
high

Exploitable
local

Bugzilla entries