Junglewise Threat Intelligence

CVE-2019-13272: Linux Kernel Improper Privilege Management Vulnerability

CVE-2019-13272 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-12-10

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel mishandles credential recording in ptrace_link within kernel/ptrace.c, leading to an improper privilege management vulnerability. Local attackers can exploit this via specific parent-child process relationships, such as using Polkit's pkexec helper with PTRACE_TRACEME, to escalate privileges to root.

Affected products

  • Linux Linux Kernel before 5.1.17

Timeline

  • 2019-07-10: patched: Fixed in Linux kernel version 5.1.17
  • 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-12-10: disclosed

Related threats