CVE-2019-13272
Description
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
EPSS (Exploit Prediction Scoring System)
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score Trend (Last 90 Days)
Linux - Broken Permission and Object Lifetime Handling …
Verified LocalLinux - Broken Permission and Object Lifetime Handling for PTRACE_TRACEME
View Exploit Code →Linux Kernel 4.10 < 5.1.17 - 'PTRACE_TRACEME' pkexec …
Linux Kernel 4.10 < 5.1.17 - 'PTRACE_TRACEME' pkexec Local Privilege Escalation
View Exploit Code →Linux Polkit - pkexec helper PTRACE_TRACEME local root …
Verified Metasploit Framework (MSF)Linux Polkit - pkexec helper PTRACE_TRACEME local root (Metasploit)
View Exploit Code →Linux Kernel 5.1.x - 'PTRACE_TRACEME' pkexec Local Privilege …
Linux Kernel 5.1.x - 'PTRACE_TRACEME' pkexec Local Privilege Escalation (2)
View Exploit Code →Linux Kernel by Linux
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Debian Linux by Debian
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
Enterprise Linux by Redhat
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
Service Processor by Netapp
cpe:2.3:a:netapp:service_processor:-:*:*:*:*:*:*:*
Linux Kernel by Linux
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Enterprise Linux For Ibm Z Systems by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0_s390x:*:*:*:*:*:*:*
H410C Firmware by Netapp
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
E-Series Performance Analyzer by Netapp
cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*
Active Iq Unified Manager by Netapp
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
Linux Kernel by Linux
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Enterprise Linux For Real Time Tus by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.8:*:*:*:*:*:*:*
Enterprise Linux For Real Time For Nfv Tus by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.6:*:*:*:*:*:*:*
Linux Kernel by Linux
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Enterprise Linux For Real Time For Nfv Tus by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.2:*:*:*:*:*:*:*
Enterprise Linux For Real Time For Nfv by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv:8.0:*:*:*:*:*:*:*
Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
Linux Kernel by Linux
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Aff A700S Firmware by Netapp
cpe:2.3:o:netapp:aff_a700s_firmware:-:*:*:*:*:*:*:*
Hci Management Node by Netapp
cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:*
Solidfire by Netapp
cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:*
Enterprise Linux For Arm 64 by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_arm_64:7.0_aarch64:*:*:*:*:*:*:*
Linux Kernel by Linux
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Hci Compute Node by Netapp
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*
Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*
Enterprise Linux For Real Time For Nfv Tus by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.4:*:*:*:*:*:*:*
Enterprise Linux For Real Time Tus by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.2:*:*:*:*:*:*:*
E-Series Santricity Os Controller by Netapp
cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*
Debian Linux by Debian
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Enterprise Linux For Real Time Tus by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.4:*:*:*:*:*:*:*
Enterprise Linux For Real Time by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_real_time:8:*:*:*:*:*:*:*
Enterprise Linux For Real Time Tus by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.6:*:*:*:*:*:*:*
Linux Kernel by Linux
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Ubuntu Linux by Canonical
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
Fedora by Fedoraproject
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
Debian Linux by Debian
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Enterprise Linux For Real Time For Nfv Tus by Redhat
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.8:*:*:*:*:*:*:*
Steelstore Cloud Integrated Storage by Netapp
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
Enterprise Linux by Redhat
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
Linux Kernel by Linux
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
H610S Firmware by Netapp
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*