Executive brief
The Linux kernel mishandles credential recording in ptrace_link within kernel/ptrace.c, leading to an improper privilege management vulnerability. Local attackers can exploit this via specific parent-child process relationships, such as using Polkit's pkexec helper with PTRACE_TRACEME, to escalate privileges to root.
Affected products
- Linux Linux Kernel before 5.1.17
Timeline
- 2019-07-10: patched: Fixed in Linux kernel version 5.1.17
- 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-12-10: disclosed