LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-13272: Linux Kernel Improper Privilege Management Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 10, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 10, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-13272 to its Known Exploited Vulnerabilities catalog on Dec 10, 2021, with a federal patch deadline of Jun 10, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Kernel/ptrace.c in Linux kernel mishandles contains an improper privilege management vulnerability that allows local users to obtain root access.

CVE-2019-13272 is an improper privilege management vulnerability in the Linux kernel that can allow a local user to obtain root access. It matters because any system running an affected kernel where untrusted or lower-privileged local accounts exist faces a direct path to full system control if the flaw is successfully abused.

Defenders should treat this as a local privilege-escalation issue in a core operating-system component. Confirm exact impact, fixed versions, and deployment guidance against the vendor advisory for your distribution.

How it works

The weakness is classified as CWE-269 (Improper Privilege Management). According to the CISA summary, code in Kernel/ptrace.c mishandles privilege checks in a way that lets local users escalate to root.

In practical terms, an attacker who already has a foothold as a non-root user on the host can abuse the flawed privilege handling around ptrace-related operations to gain elevated privileges. No remote attack vector is described in the provided facts; exploitation requires local access. Exact call sequences, required capabilities, or race conditions are not detailed here and must be confirmed against the vendor advisory rather than assumed.

Am I affected? How to find it in your systems

The vulnerability affects the Linux kernel. It typically appears on servers, workstations, containers, cloud instances, embedded devices, and any other system running a Linux kernel that has not yet received the relevant fix.

Because public detail on exact vulnerable builds is limited in the facts supplied, always cross-check the running kernel against the distribution vendor’s advisory before declaring a system clean or affected.

How to remediate

The primary action required by CISA is to apply updates per vendor instructions. Obtain and install the kernel security update that addresses CVE-2019-13272 from your Linux distribution or kernel supplier, then reboot into the new kernel.

If you can't patch immediately

When an immediate kernel update is not feasible, apply compensating controls to limit the blast radius of local privilege escalation until the patch can be installed.

These measures reduce risk but do not eliminate the underlying kernel flaw; treat them as temporary.

If your data may have been exposed

Actively exploited local privilege-escalation vulnerabilities can lead to full host compromise and subsequent data exposure or lateral movement. Known ransomware use of this specific CVE is not documented in the supplied facts. If you suspect the vulnerability was abused, follow normal incident-response steps: isolate the host, preserve volatile evidence, rotate credentials that may have been accessible, and examine the system for persistence. You can also run a free exposure scan of your email addresses to check whether those identities appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedLinux · Kernel
WeaknessCWE-269
Added to CISA KEVDec 10, 2021
Federal patch deadlineJun 10, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities