SB2019072209 - Privilege escalation in Linux Kernel ptrace_link
Published: July 22, 2019 Updated: June 21, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-13272)
CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Clear
Remediation
Install update from vendor's website.
References
- https://github.com/torvalds/linux/commit/6994eefb0053799d2e07cd140df6c2ea106c41ee
- https://cdn.kernel.org/pub/linux/kernel/v5.x/
- https://github.com/bcoles/kernel-exploits/tree/master/CVE-2019-13272
- https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/ptrace_trace...