CVE-2019-13272

Aliases:UBUNTU-CVE-2019-13272DEBIAN-CVE-2019-13272
Advisory lineage Upstream: 0 Downstream: 29
Analyzed
Published: 17 Jul 2019, 12:32
Last modified:21 Oct 2025, 23:45

Vulnerability Summary

Overall Risk (default)
high
52/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
52.2% CRITICAL
52% probability -29.05%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
10 found
Dark Web
Not detected

Timeline

17 Jul 2019, 12:32
Published
Vulnerability first disclosed
10 Dec 2021, 00:00
Added to CISA KEV
Linux Kernel Improper Privilege Management Vulnerability
10 Jun 2022, 00:00
CISA Remediation Due
Apply updates per vendor instructions.
21 Oct 2025, 23:45
Last Modified
Vulnerability information updated

Description

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 52.20% Percentile: 99%

Affected Systems

  • canonicalubuntu_linux

    16.04 | 18.04 | 19.04

  • debianlinux

    < 4.19.37-6 | < 4.19.37-6 | < 4.19.37-6 | < 4.19.37-6

  • ubuntulinux

    < 4.4.0-159.187 | < 4.15.0-58.64

  • ubuntulinux-aws

    < 4.4.0-1054.58 | < 4.4.0-1090.101 | < 4.15.0-1047.49

  • ubuntulinux-aws-fips

    < 4.15.0-2018.18 | all

  • ubuntulinux-aws-hwe

    < 4.15.0-1047.49~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1059.64~14.04.1 | < 4.15.0-1055.60 | < 5.0.0-1014.14~18.04.1

  • ubuntulinux-azure-fde

    all

  • ubuntulinux-azure-fips

    < 4.15.0-2006.7 | all

  • ubuntulinux-bluefield

    all

  • ubuntulinux-fips

    < 4.4.0-1017.22

  • ubuntulinux-gcp

    < 4.15.0-1040.42~16.04.1 | < 4.15.0-1040.42

  • ubuntulinux-gcp-fips

    all

  • ubuntulinux-gke

    all

  • ubuntulinux-gke-4.15

    < 4.15.0-1040.42

  • ubuntulinux-hwe

    < 4.15.0-58.64~16.04.1 | < 5.0.0-25.26~18.04.1

  • ubuntulinux-hwe-edge

    all

  • ubuntulinux-intel-iot-realtime

    all

  • ubuntulinux-kvm

    < 4.4.0-1054.61 | < 4.15.0-1042.42

  • ubuntulinux-lts-xenial

    < 4.4.0-164.192~14.04.1

  • ubuntulinux-oem

    < 4.15.0-1050.57

  • ubuntulinux-oem-osp1

    < 5.0.0-1018.20

  • ubuntulinux-oracle

    < 4.15.0-1021.23~16.04.1 | < 4.15.0-1021.23

  • ubuntulinux-raspi-realtime

    all

  • ubuntulinux-raspi2

    < 4.4.0-1118.127 | < 4.15.0-1043.46

  • ubuntulinux-realtime

    all

  • ubuntulinux-riscv

    all | all

  • ubuntulinux-snapdragon

    < 4.4.0-1122.128 | < 4.15.0-1060.66

  • debiandebian_linux

    8.0 | 9.0 | 10.0

  • fedoraprojectfedora

    29

  • linuxlinux_kernel

    ≥ 3.16.52, < 3.16.71 | ≥ 4.1.39, < 4.2 | ≥ 4.4.40, < 4.4.185 | ≥ 4.8.16, < 4.9 | ≥ 4.9.1, < 4.9.185 | ≥ 4.10, < 4.14.133 | ≥ 4.15, < 4.19.58 | ≥ 4.20, < 5.1.17

  • netappactive_iq_unified_manager

    na

  • netappaff_a700s_firmware

    na

  • netappe-series_performance_analyzer

    na

  • netappe-series_santricity_os_controller

    ≥ 11.0.0, ≤ 11.60.3

  • netapph410c_firmware

    na

  • netapph610s_firmware

    na

  • netapphci_compute_node

    na

  • netapphci_management_node

    na

  • netappservice_processor

    na

  • netappsolidfire

    na

  • netappsteelstore_cloud_integrated_storage

    na

  • redhatenterprise_linux

    7.0 | 8.0

  • redhatenterprise_linux_for_arm_64

    7.0_aarch64

  • redhatenterprise_linux_for_ibm_z_systems

    7.0_s390x

  • redhatenterprise_linux_for_real_time

    8

  • redhatenterprise_linux_for_real_time_for_nfv

    8.0

  • redhatenterprise_linux_for_real_time_for_nfv_tus

    8.2 | 8.4 | 8.6 | 8.8

  • redhatenterprise_linux_for_real_time_tus

    8.2 | 8.4 | 8.6 | 8.8

References (39)