⚠ Actively exploited
Added to CISA KEV on 2021-12-10. Federal agencies required to patch by 2022-06-10. Required action: Apply updates per vendor instructions..

CVE-2019-13272

20 documents12 sources
7.8
CVSS
HIGH
EPSS80.6%(99th)
CISA KEVPublic ExploitExploited in Wild
CISA Required Action: Apply updates per vendor instructions.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

NVDlinux/linux_kernel3.16.523.16.71+7
Debianlinux< 4.19.37-6+3

Also affects: Enterprise Linux 7.0, 8.0, 8, 8.2, 8.4, 8.6, 8.8, Debian Linux 10.0, 8.0, 9.0, Ubuntu Linux 16.04, 18.04, 19.04, Fedora 29

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is i

🔴Vulnerability Details

4
GHSA
GHSA-87j5-gppq-mq6h: In the Linux kernel before 52022-05-24
OSV
CVE-2019-13272: In the Linux kernel before 52019-07-17
CVEList
CVE-2019-13272: In the Linux kernel before 52019-07-17
VulnCheck
Linux Kernel Improper Privilege Management Vulnerability2019

💥Exploits & PoCs

4
Exploit-DB
Linux Kernel 5.1.x - 'PTRACE_TRACEME' pkexec Local Privilege Escalation (2)2021-11-23
Exploit-DB
Linux Polkit - pkexec helper PTRACE_TRACEME local root (Metasploit)2019-10-24
Exploit-DB
Linux Kernel 4.10 < 5.1.17 - 'PTRACE_TRACEME' pkexec Local Privilege Escalation2019-07-24
Exploit-DB
Linux - Broken Permission and Object Lifetime Handling for PTRACE_TRACEME2019-07-17

🔍Detection Rules

1
YARA
Linux_Exploit_CVE_2019_13272_583dd2c0

📋Vendor Advisories

8
CISA
Linux Kernel Improper Privilege Management Vulnerability2021-12-10
Ubuntu
Linux kernel (AWS) vulnerabilities2019-09-02
Ubuntu
Linux kernel (AWS) vulnerabilities2019-09-02
Ubuntu
Linux kernel vulnerabilities2019-08-13
Ubuntu
Linux kernel vulnerabilities2019-08-13

💬Community

2
Bugzilla
CVE-2019-13272 kernel: broken permission and object lifetime handling for PTRACE_TRACEME2019-07-17
Bugzilla
CVE-2019-13272 kernel: broken permission and object lifetime handling for PTRACE_TRACEME [fedora-all]2019-07-17
CVE-2019-13272 (HIGH CVSS 7.8) | In the Linux kernel before 5.1.17 | cvebase.io