Vulnerability Intelligence Report
Linux Kernel Improper Privilege Management Vulnerability
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:52.20%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-269 ↗CWE-269 (via CISA KEV)
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| linux | linux_kernel | all |
| debian | debian_linux | 8.0, 9.0, 10.0 |
| fedoraproject | fedora | 29 |
| canonical | ubuntu_linux | 16.04, 18.04, 19.04 |
| redhat | enterprise_linux | 7.0, 8.0 |
| redhat | enterprise_linux_for_arm_64 | 7.0_aarch64 |
| redhat | enterprise_linux_for_ibm_z_systems | 7.0_s390x |
| redhat | enterprise_linux_for_real_time | 8 |
| redhat | enterprise_linux_for_real_time_for_nfv | 8.0 |
| redhat | enterprise_linux_for_real_time_for_nfv_tus | 8.2, 8.4, 8.6, 8.8 |
| redhat | enterprise_linux_for_real_time_tus | 8.2, 8.4, 8.6, 8.8 |
| netapp | aff_a700s_firmware | all |
| netapp | aff_a700s | all |
| netapp | h410c_firmware | all |
| netapp | h410c | all |
| netapp | h610s_firmware | all |
| netapp | h610s | all |
| netapp | active_iq_unified_manager | all |
| netapp | e-series_performance_analyzer | all |
| netapp | e-series_santricity_os_controller | all |
| netapp | hci_management_node | all |
| netapp | service_processor | all |
| netapp | solidfire | all |
| netapp | steelstore_cloud_integrated_storage | all |
| netapp | hci_compute_node | all |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2019-07-04T00:00:00 |
| Published | 2019-07-17T12:32:55 |
| Last Updated | 2025-10-21T23:45:33 |
Community Chatter & Buzz