In the Linux kernel before 5.1.17, ptracelink in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACETRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
[
{
"events": [
{
"introduced": "3.16.52"
},
{
"fixed": "3.16.71"
}
]
},
{
"events": [
{
"introduced": "4.1.39"
},
{
"fixed": "4.2"
}
]
},
{
"events": [
{
"introduced": "4.4.40"
},
{
"fixed": "4.4.185"
}
]
},
{
"events": [
{
"introduced": "4.8.16"
},
{
"fixed": "4.9"
}
]
},
{
"events": [
{
"introduced": "4.9.1"
},
{
"fixed": "4.9.185"
}
]
},
{
"events": [
{
"introduced": "4.10"
},
{
"fixed": "4.14.133"
}
]
},
{
"events": [
{
"introduced": "4.15"
},
{
"fixed": "4.19.58"
}
]
},
{
"events": [
{
"introduced": "4.20"
},
{
"fixed": "5.1.17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "10.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "29"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "18.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "19.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0_aarch64"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "7.0_s390x"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "8.8"
}
]
},
{
"events": [
{
"introduced": "11.0.0"
},
{
"last_affected": "11.60.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"fixed": "5.1.17"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-13272.json"