CVE-2019-13272 vulnerability in Debian and Other Products
Published on July 17, 2019






Known Exploited Vulnerability
This Linux Kernel Improper Privilege Management Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability which allows local users to obtain root access.
The following remediation steps are recommended / required by June 10, 2022: Apply updates per vendor instructions.
Vulnerability Analysis
CVE-2019-13272 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. It has an exploitability score of 1.8 out of four. The potential impact of an exploit of this vulnerability is considered to be very high.
Improper Privilege Management
The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Products Associated with CVE-2019-13272
You can be notified by stack.watch whenever vulnerabilities like CVE-2019-13272 are published in these products:
What versions are vulnerable to CVE-2019-13272?
-
Linux Kernel Version 4.10 Fixed in Version 4.14.133
-
Linux Kernel Version 4.20 Fixed in Version 5.1.17
-
Linux Kernel Version 4.15 Fixed in Version 4.19.58
-
Linux Kernel Version 3.16.52 Fixed in Version 3.16.71
-
Linux Kernel Version 4.9.1 Fixed in Version 4.9.185
-
Linux Kernel Version 4.1.39 Fixed in Version 4.2
-
Linux Kernel Version 4.4.40 Fixed in Version 4.4.185
-
Linux Kernel Version 4.8.16 Fixed in Version 4.9
-
Debian Linux Version 8.0
-
Debian Linux Version 9.0
-
Debian Linux Version 10.0
-
Fedora Project Fedora Version 29
-
Canonical Ubuntu Linux Version 18.04
-
Canonical Ubuntu Linux Version 19.04
-
Canonical Ubuntu Linux Version 16.04
-
Red Hat Enterprise Linux (RHEL) Version 7.0
-
Red Hat Enterprise Linux (RHEL) Version 8.0
-
Red Hat Enterprise Linux For Real Time Version 8
Each of the following must match for the vulnerability to exist.
Each of the following must match for the vulnerability to exist.
Each of the following must match for the vulnerability to exist.
-
NetApp Steelstore Cloud Integrated Storage Version -
-
NetApp Service Processor Version -
-
NetApp Solidfire Version -
-
NetApp Hci Management Node Version -
-
NetApp Active Iq Unified Manager Version - vmware_vsphere
-
NetApp E Series Performance Analyzer Version -
-
NetApp Hci Compute Node Version -
-
NetApp E Series Santricity Os Controller Version 11.0.0 through 11.60.3