CVE-2019-13272

Advisory lineage Upstream: 0 Downstream: 29
Analyzed
Published: 17 Jul 2019, 12:32
Last modified:21 Oct 2025, 23:45

Vulnerability Summary

Overall Risk (default)
high
57/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
80.38% CRITICAL
80% probability -0.87%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
10 found
Dark Web
Not detected

Timeline

17 Jul 2019, 12:32
Published
Vulnerability first disclosed
10 Dec 2021, 00:00
Added to CISA KEV
Linux Kernel Improper Privilege Management Vulnerability
10 Jun 2022, 00:00
CISA Remediation Due
Apply updates per vendor instructions.
21 Oct 2025, 23:45
Last Modified
Vulnerability information updated

Description

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 80.38% Percentile: 99%

Affected Systems

  • canonicalubuntu_linux

    16.04 | 18.04 | 19.04

  • debiandebian_linux

    8.0 | 9.0 | 10.0

  • fedoraprojectfedora

    29

  • linuxlinux_kernel

    ≥ 3.16.52, < 3.16.71 | ≥ 4.1.39, < 4.2 | ≥ 4.4.40, < 4.4.185 | ≥ 4.8.16, < 4.9 | ≥ 4.9.1, < 4.9.185 | ≥ 4.10, < 4.14.133 | ≥ 4.15, < 4.19.58 | ≥ 4.20, < 5.1.17

  • netappactive_iq_unified_manager

    na

  • netappaff_a700s

    na

  • netappe-series_performance_analyzer

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0.0, ≤ 11.60.3

  • netapph410c_firmware

    na

  • netapph610s_firmware

    na

  • netapphci_compute_node_firmware

    na

  • netapphci_management_node

    na

  • netappservice_processor

    na

  • netappsolidfire

    na

  • netappsteelstore_cloud_integrated_storage

    na

  • redhatenterprise_linux

    7.0 | 8.0

  • redhatenterprise_linux_for_arm_64

    7.0_aarch64

  • redhatenterprise_linux_for_ibm_z_systems

    7.0_s390x

  • redhatenterprise_linux_for_real_time

    8

  • redhatenterprise_linux_for_real_time_for_nfv

    8.0

  • redhatenterprise_linux_for_real_time_for_nfv_tus

    8.2 | 8.4 | 8.6 | 8.8

  • redhatenterprise_linux_for_real_time_tus

    8.2 | 8.4 | 8.6 | 8.8

References (30)