CVE-2019-13272

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
mitreCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
VendorProductVersion
linuxlinux_kernel
3.16.52 ≤
𝑥
< 3.16.71
linuxlinux_kernel
4.1.39 ≤
𝑥
< 4.2
linuxlinux_kernel
4.4.40 ≤
𝑥
< 4.4.185
linuxlinux_kernel
4.8.16 ≤
𝑥
< 4.9
linuxlinux_kernel
4.9.1 ≤
𝑥
< 4.9.185
linuxlinux_kernel
4.10 ≤
𝑥
< 4.14.133
linuxlinux_kernel
4.15 ≤
𝑥
< 4.19.58
linuxlinux_kernel
4.20 ≤
𝑥
< 5.1.17
debiandebian_linux
8.0
debiandebian_linux
9.0
debiandebian_linux
10.0
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
19.04
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux_for_arm_64
7.0_aarch64:_aarch64
redhatenterprise_linux_for_ibm_z_systems
7.0_s390x:_s390x
redhatenterprise_linux_for_real_time_for_nfv
8.0
redhatenterprise_linux_for_real_time_for_nfv_tus
8.2
redhatenterprise_linux_for_real_time_for_nfv_tus
8.4
redhatenterprise_linux_for_real_time_for_nfv_tus
8.6
redhatenterprise_linux_for_real_time_for_nfv_tus
8.8
redhatenterprise_linux_for_real_time_tus
8.2
redhatenterprise_linux_for_real_time_tus
8.4
redhatenterprise_linux_for_real_time_tus
8.6
redhatenterprise_linux_for_real_time_tus
8.8
netappaff_a700s_firmware
-
netapph410c_firmware
-
netapph610s_firmware
-
netappactive_iq_unified_manager
-
netappe-series_performance_analyzer
-
netappe-series_santricity_os_controller
11.0.0 ≤
𝑥
≤ 11.60.3
netapphci_management_node
-
netappservice_processor
-
netappsolidfire
-
netappsteelstore_cloud_integrated_storage
-
netapphci_compute_node
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bullseye
5.10.223-1
fixed
bullseye (security)
5.10.226-1
fixed
bookworm
6.1.106-3
fixed
bookworm (security)
6.1.112-1
fixed
trixie
6.11.5-1
fixed
sid
6.11.6-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
eoan
not-affected
disco
Fixed 5.0.0-25.26
released
cosmic
ignored
bionic
Fixed 4.15.0-58.64
released
xenial
Fixed 4.4.0-159.187
released
trusty
not-affected
linux-aws
eoan
not-affected
disco
Fixed 5.0.0-1014.16
released
cosmic
ignored
bionic
Fixed 4.15.0-1047.49
released
xenial
Fixed 4.4.0-1090.101
released
trusty
ignored
linux-aws-5.0
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-aws-hwe
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
Fixed 4.15.0-1047.49~16.04.1
released
trusty
dne
linux-azure
eoan
not-affected
disco
Fixed 5.0.0-1014.14
released
cosmic
ignored
bionic
Fixed 5.0.0-1014.14~18.04.1
released
xenial
Fixed 4.15.0-1055.60
released
trusty
ignored
linux-azure-5.3
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-azure-edge
eoan
dne
disco
dne
cosmic
dne
bionic
Fixed 5.0.0-1014.14~18.04.1
released
xenial
Fixed 4.15.0-1055.60
released
trusty
dne
linux-euclid
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
ignored
trusty
dne
linux-flo
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
ignored
trusty
dne
linux-gcp
eoan
not-affected
disco
Fixed 5.0.0-1013.13
released
cosmic
ignored
bionic
Fixed 4.15.0-1040.42
released
xenial
Fixed 4.15.0-1040.42~16.04.1
released
trusty
dne
linux-gcp-5.3
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-gcp-edge
eoan
dne
disco
dne
cosmic
dne
bionic
Fixed 4.15.0-1040.42
released
xenial
dne
trusty
dne
linux-gke
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
ignored
trusty
dne
linux-gke-4.15
eoan
dne
disco
dne
bionic
Fixed 4.15.0-1040.42
released
xenial
dne
trusty
dne
linux-gke-5.0
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-goldfish
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
ignored
trusty
dne
linux-grouper
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
dne
linux-hwe
eoan
dne
disco
dne
cosmic
dne
bionic
Fixed 5.0.0-25.26~18.04.1
released
xenial
Fixed 4.15.0-58.64~16.04.1
released
trusty
dne
linux-hwe-edge
eoan
dne
disco
dne
cosmic
dne
bionic
ignored
xenial
Fixed 4.15.0-58.64~16.04.1
released
trusty
dne
linux-kvm
eoan
not-affected
disco
Fixed 5.0.0-1013.14
released
cosmic
ignored
bionic
Fixed 4.15.0-1042.42
released
xenial
Fixed 4.4.0-1054.61
released
trusty
dne
linux-lts-trusty
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
dne
linux-lts-utopic
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
dne
linux-lts-vivid
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
dne
linux-lts-wily
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
dne
linux-lts-xenial
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
ignored
linux-maguro
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
dne
linux-mako
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
ignored
trusty
dne
linux-manta
eoan
dne
disco
dne
cosmic
dne
bionic
dne
xenial
dne
trusty
dne
linux-oem
eoan
Fixed 4.15.0-1050.57
released
disco
Fixed 4.15.0-1050.57
released
cosmic
ignored
bionic
Fixed 4.15.0-1050.57
released
xenial
ignored
trusty
dne
linux-oem-5.4
eoan
dne
bionic
dne
xenial
dne
trusty
dne
linux-oem-osp1
eoan
Fixed 5.0.0-1018.20
released
disco
ignored
bionic
Fixed 5.0.0-1018.20
released
xenial
dne
trusty
dne
linux-oracle
eoan
not-affected
disco
Fixed 5.0.0-1004.8
released
cosmic
ignored
bionic
Fixed 4.15.0-1021.23
released
xenial
Fixed 4.15.0-1021.23~16.04.1
released
trusty
dne
linux-oracle-5.0
eoan
dne
disco
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-raspi2
eoan
not-affected
disco
Fixed 5.0.0-1014.14
released
cosmic
ignored
bionic
Fixed 4.15.0-1043.46
released
xenial
Fixed 4.4.0-1118.127
released
trusty
dne
linux-raspi2-5.3
eoan
dne
bionic
not-affected
xenial
dne
trusty
dne
linux-snapdragon
eoan
dne
disco
Fixed 5.0.0-1018.19
released
cosmic
dne
bionic
Fixed 4.15.0-1060.66
released
xenial
Fixed 4.4.0-1122.128
released
trusty
dne
References