7.8

CVE-2019-13272

Warning
Exploit

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version >= 3.16.52 < 3.16.71
LinuxLinux Kernel Version >= 4.1.39 < 4.2
LinuxLinux Kernel Version >= 4.4.40 < 4.4.185
LinuxLinux Kernel Version >= 4.8.16 < 4.9
LinuxLinux Kernel Version >= 4.9.1 < 4.9.185
LinuxLinux Kernel Version >= 4.10 < 4.14.133
LinuxLinux Kernel Version >= 4.15 < 4.19.58
LinuxLinux Kernel Version >= 4.20 < 5.1.17
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
FedoraprojectFedora Version29
CanonicalUbuntu Linux Version16.04 SwEditionesm
CanonicalUbuntu Linux Version18.04 SwEditionesm
CanonicalUbuntu Linux Version19.04
RedhatEnterprise Linux Version7.0
RedhatEnterprise Linux Version8.0
RedhatEnterprise Linux For Arm 64 Version7.0_aarch64
NetappAff A700s Firmware Version-
   NetappAff A700s Version-
NetappH410c Firmware Version-
   NetappH410c Version-
NetappH610s Firmware Version-
   NetappH610s Version-
NetappActive Iq Unified Manager Version- SwPlatformvmware_vsphere
NetappE-series Santricity Os Controller Version >= 11.0.0 <= 11.60.3
NetappService Processor Version-
NetappSolidfire Version-
NetappHci Compute Node Version-

10.12.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Linux Kernel Improper Privilege Management Vulnerability

Vulnerability

Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.

Description

Apply updates per vendor instructions.

Required actions
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 81.24% 0.991
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
https://usn.ubuntu.com/4094-1/
Third Party Advisory
https://usn.ubuntu.com/4118-1/
Third Party Advisory
https://usn.ubuntu.com/4095-1/
Third Party Advisory
https://seclists.org/bugtraq/2019/Jul/33
Third Party Advisory
Mailing List
Issue Tracking
https://usn.ubuntu.com/4117-1/
Third Party Advisory
https://usn.ubuntu.com/4093-1/
Third Party Advisory
https://seclists.org/bugtraq/2019/Jul/30
Third Party Advisory
Mailing List
Issue Tracking
https://bugs.chromium.org/p/project-zero/issues/detail?id=1903
Patch
Third Party Advisory
Exploit
Issue Tracking
https://bugzilla.suse.com/show_bug.cgi?id=1140671
Patch
Third Party Advisory
Issue Tracking