CVE-2019-13272
Confirmed PUBLISHEDIn the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a...
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
- CVE Published
- Jul 17, 2019
- Exploitation Reported
- Dec 10, 2021
- CVSS
- 7.8 High
- EPSS
- —
Affected Versions
| Vendor | Product | Version | Status |
|---|---|---|---|
| n/a |
n/a
|
n/a |
Affected |
CVE References
- FEDORA-2019-a95015e60f lists.fedoraproject.org · Vendor Advisory https://lists.fedoraproject.org/archives/list/package-announce%40list...
- DSA-4484 debian.org · Vendor Advisory https://www.debian.org/security/2019/dsa-4484
- RHSA-2019:2405 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2019:2405
- RHSA-2019:2411 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2019:2411
- USN-4093-1 usn.ubuntu.com · Vendor Advisory https://usn.ubuntu.com/4093-1/
Show 24 more references
- USN-4094-1 usn.ubuntu.com · Vendor Advisory https://usn.ubuntu.com/4094-1/
- USN-4095-1 usn.ubuntu.com · Vendor Advisory https://usn.ubuntu.com/4095-1/
- USN-4117-1 usn.ubuntu.com · Vendor Advisory https://usn.ubuntu.com/4117-1/
- USN-4118-1 usn.ubuntu.com · Vendor Advisory https://usn.ubuntu.com/4118-1/
- RHSA-2019:2809 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2019:2809
- 20190722 [SECURITY] [DSA 4484-1] linux security update seclists.org · Mailing List https://seclists.org/bugtraq/2019/Jul/30
- 20190722 [slackware-security] Slackware 14.2 kernel (SSA:2019-202-01) seclists.org · Mailing List https://seclists.org/bugtraq/2019/Jul/33
- [debian-lts-announce] 20190723 [SECURITY] [DLA 1862-1] linux security update lists.debian.org · Mailing List https://lists.debian.org/debian-lts-announce/2019/07/msg00022.html
- [debian-lts-announce] 20190723 [SECURITY] [DLA 1863-1] linux-4.9 security update lists.debian.org · Mailing List https://lists.debian.org/debian-lts-announce/2019/07/msg00023.html
- packetstormsecurity.com/files/153663/Linux-PTRACE_TRACEME-Broken-Per... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/153663/Linux-PTRACE_TRACEME-Brok...
- bugs.chromium.org/p/project-zero/issues/detail bugs.chromium.org · CVE Record https://bugs.chromium.org/p/project-zero/issues/detail?id=1903
- cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.1.17 cdn.kernel.org · CVE Record https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.1.17
- GitHub — torvalds/linux github.com · CVE Record https://github.com/torvalds/linux/commit/6994eefb0053799d2e07cd140df6...
- git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit git.kernel.org · CVE Record https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commi...
- bugzilla.suse.com/show_bug.cgi bugzilla.suse.com · CVE Record https://bugzilla.suse.com/show_bug.cgi?id=1140671
- bugzilla.redhat.com/show_bug.cgi bugzilla.redhat.com · CVE Record https://bugzilla.redhat.com/show_bug.cgi?id=1730895
- packetstormsecurity.com/files/153702/Slackware-Security-Advisory-Sla... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/153702/Slackware-Security-Adviso...
- security.netapp.com/advisory/ntap-20190806-0001 security.netapp.com · CVE Record https://security.netapp.com/advisory/ntap-20190806-0001/
- packetstormsecurity.com/files/154245/Kernel-Live-Patch-Security-Noti... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/154245/Kernel-Live-Patch-Securit...
- support.f5.com/csp/article/K91025336 support.f5.com · CVE Record https://support.f5.com/csp/article/K91025336
- support.f5.com/csp/article/K91025336 support.f5.com · CVE Record https://support.f5.com/csp/article/K91025336?utm_source=f5support&...
- packetstormsecurity.com/files/154957/Linux-Polkit-pkexec-Helper-PTRA... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/154957/Linux-Polkit-pkexec-Helpe...
- packetstormsecurity.com/files/156929/Linux-PTRACE_TRACEME-Local-Root... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/156929/Linux-PTRACE_TRACEME-Loca...
- packetstormsecurity.com/files/165051/Linux-Kernel-5.1.x-PTRACE_TRACE... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/165051/Linux-Kernel-5.1.x-PTRACE...
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2021-12-10 00:00 UTC |
Scanner Artifacts
Nuclei and Metasploit references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/ptrace_traceme_pkexec_helper.rb | Apr 28, 2025 |
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
Exploitation Status
Exploited in the wild
Recorded 2021-12-10 00:00:00 UTC · CISA
Proof of concept available
Recorded 2019-07-31 04:51:43 UTC · GitHub
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/ptrace_traceme_pkexec_helper.rb | Apr 28, 2025 |
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2024-06-20 10:04:13 UTC · 2 stars
This is a Python 3 version of this exploit. Hope it works!!!
github · Created 2024-01-31 21:50:04 UTC · 2 stars
Es una vulnerabilidad para escalar privilegios en linux.
github · Created 2023-09-04 15:16:09 UTC · 0 stars
github · Created 2022-03-10 01:27:46 UTC · 0 stars
github · Created 2020-10-19 02:33:29 UTC · 0 stars
github · Created 2019-07-31 06:36:21 UTC · 5 stars
The exploit for CVE-2019-13272
github · Created 2019-07-31 04:51:43 UTC · 330 stars
Linux 4.10 < 5.1.17 PTRACE_TRACEME local root
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
15:02 UTC about 1 year ago15:02 UTC · about 1 year ago
Metasploit module available
Exploit module available
-
00:00 UTC over 4 years ago00:00 UTC · over 4 years ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
04:51 UTC almost 7 years ago04:51 UTC · almost 7 years ago
Public PoC available
Public proof-of-concept code published
-
12:32 UTC about 7 years ago12:32 UTC · about 7 years ago
CVE published
Vulnerability disclosed publicly
-
00:00 UTC about 7 years ago00:00 UTC · about 7 years ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2019-13272
{
"cve_id": "CVE-2019-13272",
"title": "In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles ...",
"affected_vendor": "Linux",
"affected_product": "kernel",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 7.8,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}