{"id":"CVE-2019-13272","details":"In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.","modified":"2026-04-11T12:10:33.580902Z","published":"2019-07-17T13:15:10.687Z","related":["SUSE-SU-2019:2949-1","SUSE-SU-2019:2984-1","SUSE-SU-2019:3223-1","SUSE-SU-2019:3224-1","SUSE-SU-2019:3225-1","SUSE-SU-2019:3228-1","SUSE-SU-2019:3230-1","SUSE-SU-2019:3232-1","SUSE-SU-2019:3246-1","SUSE-SU-2019:3247-1","SUSE-SU-2019:3248-1","SUSE-SU-2019:3249-1","SUSE-SU-2019:3252-1","SUSE-SU-2019:3258-1","SUSE-SU-2019:3260-1","SUSE-SU-2019:3261-1","SUSE-SU-2019:3263-1"],"database_specific":{"unresolved_ranges":[{"cpe":"cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"11.0.0"},{"last_affected":"11.60.3"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*","extracted_events":[{"last_affected":"16.04"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","cpe":"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*","extracted_events":[{"last_affected":"18.04"}]},{"source":"CPE_FIELD","cpe":"cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"19.04"}]},{"extracted_events":[{"last_affected":"10.0"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"8.0"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"},{"extracted_events":[{"last_affected":"9.0"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"29"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.16.52"},{"fixed":"3.16.71"},{"introduced":"4.4.40"},{"fixed":"4.4.185"},{"introduced":"4.9.1"},{"fixed":"4.9.185"},{"introduced":"4.10"},{"fixed":"4.14.133"},{"introduced":"4.15"},{"fixed":"4.19.58"},{"introduced":"4.20"},{"fixed":"5.1.17"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"7.0"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"8.0"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_for_arm_64:7.0_aarch64:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"7.0_aarch64"}],"source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"7.0_s390x"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0_s390x:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_for_real_time:8:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"8"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv:8.0:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"8.0"}],"source":"CPE_FIELD"},{"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.2:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"8.2"}]},{"extracted_events":[{"last_affected":"8.4"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.4:*:*:*:*:*:*:*"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.6:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"8.6"}],"source":"CPE_FIELD"},{"extracted_events":[{"last_affected":"8.8"}],"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.8:*:*:*:*:*:*:*"},{"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.2:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"8.2"}]},{"source":"CPE_FIELD","cpe":"cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.4:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"8.4"}]},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.6:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"8.6"}],"source":"CPE_FIELD"},{"cpe":"cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.8:*:*:*:*:*:*:*","extracted_events":[{"last_affected":"8.8"}],"source":"CPE_FIELD"}]},"references":[{"type":"WEB","url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-13272"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/153663/Linux-PTRACE_TRACEME-Broken-Permission-Object-Lifetime-Handling.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:2405"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:2411"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:2809"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00022.html"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00023.html"},{"type":"ADVISORY","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OGRK5LYWBJ4E4SRI4DKX367NHYSI3VOH/"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20190806-0001/"},{"type":"ADVISORY","url":"https://support.f5.com/csp/article/K91025336"},{"type":"ADVISORY","url":"https://support.f5.com/csp/article/K91025336?utm_source=f5support&amp%3Butm_medium=RSS"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4093-1/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4094-1/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4095-1/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4117-1/"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4118-1/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2019/dsa-4484"},{"type":"REPORT","url":"https://seclists.org/bugtraq/2019/Jul/30"},{"type":"REPORT","url":"https://seclists.org/bugtraq/2019/Jul/33"},{"type":"FIX","url":"https://bugs.chromium.org/p/project-zero/issues/detail?id=1903"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1730895"},{"type":"FIX","url":"https://bugzilla.suse.com/show_bug.cgi?id=1140671"},{"type":"FIX","url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.1.17"},{"type":"FIX","url":"https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=6994eefb0053799d2e07cd140df6c2ea106c41ee"},{"type":"FIX","url":"https://github.com/torvalds/linux/commit/6994eefb0053799d2e07cd140df6c2ea106c41ee"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/154245/Kernel-Live-Patch-Security-Notice-LSN-0054-1.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/154957/Linux-Polkit-pkexec-Helper-PTRACE_TRACEME-Local-Root.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/156929/Linux-PTRACE_TRACEME-Local-Root.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/165051/Linux-Kernel-5.1.x-PTRACE_TRACEME-pkexec-Local-Privilege-Escalation.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git","events":[{"introduced":"0"},{"fixed":"6994eefb0053799d2e07cd140df6c2ea106c41ee"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13272.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/torvalds/linux","events":[{"introduced":"0"},{"fixed":"64291f7db5bd8150a74ad2036f1037e6a0428df2"},{"fixed":"69973b830859bc6529a7a0468ba0d80ee5117826"},{"fixed":"6994eefb0053799d2e07cd140df6c2ea106c41ee"}],"database_specific":{"cpe":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.1.39"},{"fixed":"4.2"},{"introduced":"4.8.16"},{"fixed":"4.9"}],"source":["CPE_FIELD","REFERENCES"]}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13272.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}