peter bassill · operator
$ cve CVE-2019-13272 JSON

CVE-2019-13272 KEV EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 52.2% (pctl 99)

Patch first

On CISA KEV — known exploited in the wild, due 2022-06-10.

Description

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS52.2% — more likely to be exploited than 99% of all CVEs
On CISA KEVyes — remediate by 2022-06-10
Public exploityes
Published2019-07-17
Last modified2026-06-17

CISA KEV

NameLinux Kernel Improper Privilege Management Vulnerability
Added2021-12-10
Due2022-06-10
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (25)

VendorProduct
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
linuxlinux kernel
netappactive iq unified manager
netappaff a700s
netappaff a700s firmware
netappe-series performance analyzer
netappe-series santricity os controller
netapph410c
netapph410c firmware
netapph610s
netapph610s firmware
netapphci compute node
netapphci management node
netappservice processor
netappsolidfire
netappsteelstore cloud integrated storage
redhatenterprise linux
redhatenterprise linux for arm 64
redhatenterprise linux for ibm z systems
redhatenterprise linux for real time
redhatenterprise linux for real time for nfv
redhatenterprise linux for real time for nfv tus
redhatenterprise linux for real time tus

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD