Ubuntu Linux impacted by decade-old 'needrestart' flaw that gives root
bleepingcomputer.com
bleepingcomputer.com
The alternative approach is to just reboot after every upgrade like on Windows. That can be disruptive in some situations so needrestart was created to only restart the things that need restarting.
Most solutions in engineering involve a trade-off. Clearly this solution trades simplicity for complexity and multiple CVEs. An OS could utilise a known static configuration as described by its packaging system, for a much simpler solution. It could disallow running services any other way.
The article is incorrect in implying that users must either upgrade to needrestart 3.8 or adjust configuration to mitigate. If you're using Debian or Ubuntu, the correct thing to is to upgrade to the distribution's already patched version by using the usual "apt update && apt upgrade". This won't take you up to 3.8 but will fix the issue, as is the point of stable distribution releases.
On Ubuntu, this is automatic since unattended-upgrades installs security upgrades nightly by default.