CVE-2019-13272: Linux Kernel Improper Privilege Management Vulnerability

High severity, CVSS 7.8. Actively exploited: in CISA KEV since 2021-12-10. EPSS: 52.2% chance of exploitation in the next 30 days.

In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Fedoraproject Fedora: version 29 only
  • Linux Linux Kernel: from 3.16.52, before 3.16.71 (fixed in 3.16.71); from 4.1.39, before 4.2 (fixed in 4.2); from 4.4.40, before 4.4.185 (fixed in 4.4.185); from 4.8.16, before 4.9 (fixed in 4.9); from 4.9.1, before 4.9.185 (fixed in 4.9.185); from 4.10, before 4.14.133 (fixed in 4.14.133); …
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Aff a700s Firmware: affected versions not specified
  • Netapp E-Series Performance Analyzer: affected versions not specified
  • Netapp E-Series Santricity OS Controller: from 11.0.0, up to and including 11.60.3
  • Netapp h410c Firmware: affected versions not specified
  • Netapp h610s Firmware: affected versions not specified
  • Netapp Hci Compute Node: affected versions not specified
  • Netapp Hci Management Node: affected versions not specified
  • Netapp Service Processor: affected versions not specified
  • Netapp Solidfire: affected versions not specified
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
  • Red Hat Enterprise Linux For Arm 64: version 7.0_aarch64 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 7.0_s390x only
  • Red Hat Enterprise Linux For Real Time: version 8 only
  • Red Hat Enterprise Linux For Real Time For Nfv: version 8.0 only
  • Red Hat Enterprise Linux For Real Time For Nfv Tus: version 8.2 only; version 8.4 only; version 8.6 only; version 8.8 only
  • Red Hat Enterprise Linux For Real Time Tus: version 8.2 only; version 8.4 only; version 8.6 only; version 8.8 only

Published 2019-07-17. Last modified 2026-06-17.