cbcvebase.
CVE-2019-13272
published 2019-07-17

CVE-2019-13272: In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-06-10
Exploited in the wild
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 4.19.37-6 (bookworm)linux 4.19.37-6 (bookworm)
fedoraprojectfedora
linuxlinux_kernel>= 0 < 4.19.37-64.19.37-6
linuxlinux_kernel>= 0 < 4.19.37-64.19.37-6
linuxlinux_kernel>= 0 < 4.19.37-64.19.37-6
linuxlinux_kernel>= 0 < 4.19.37-64.19.37-6
linuxlinux_kernel>= 0 < 4.4.0-159.1874.4.0-159.187
linuxlinux_kernel>= 0 < 4.15.0-58.644.15.0-58.64
linuxlinux_kernel>= 3.16.52 < 3.16.713.16.71
linuxlinux_kernel>= 4.1.39 < 4.24.2
linuxlinux_kernel>= 4.10 < 4.14.1334.14.133
linuxlinux_kernel>= 4.15 < 4.19.584.19.58
linuxlinux_kernel>= 4.20 < 5.1.175.1.17
linuxlinux_kernel>= 4.4.40 < 4.4.1854.4.185
linuxlinux_kernel>= 4.8.16 < 4.94.9
linuxlinux_kernel>= 4.9.1 < 4.9.1854.9.185
netappe-series_santricity_os_controller11.0.0 – 11.60.3
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vulncheck7.8HIGH
cisa7.8HIGH