{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3oredhatenterprise_linux_for_real_time8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_for_arm_64:7.0_aarch64:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0_s390x:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_for_real_time:8:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv:8.0:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.2:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.4:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.6:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.8:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.2:*:*:*:*:*:*:*","cpe:2.3:o:redhat:enterprise_linux_for_real_time_tus:8.4:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2019-13272"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Linux Kernel (\u003c 5.1.17)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2019-13272 is a local privilege escalation vulnerability affecting Linux kernel versions prior to 5.1.17. The flaw resides in the ptrace_link function within kernel/ptrace.c, where the kernel mishandles the recording of credentials during the establishment of a ptrace relationship. An unprivileged local user can exploit this behavior by creating a specific parent-child process relationship where the parent drops privileges and calls execve, allowing an attacker to exert control. The exploit leverages privileged tracing through mechanisms such as the PTRACE_TRACEME request, often targeting setuid binaries like pkexec to obtain root-level execution. The recent publication of functional proof-of-concept code on Sploitus has significantly increased the risk of exploitation for legacy and unpatched systems.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker gains initial access to the target system as a low-privileged user.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies or executes a vulnerable target binary (e.g., /usr/bin/pkexec or similar suid-privileged helpers).\u003c/li\u003e\n\u003cli\u003eThe attacker initiates a ptrace relationship using the PTRACE_TRACEME request targeting the chosen helper.\u003c/li\u003e\n\u003cli\u003eThe parent process drops privileges while keeping the ptrace relationship active.\u003c/li\u003e\n\u003cli\u003eThe parent process calls execve, triggering the ptrace_link credential mishandling in the kernel.\u003c/li\u003e\n\u003cli\u003eThe kernel incorrectly records the credentials, allowing the child process to retain or gain elevated root privileges.\u003c/li\u003e\n\u003cli\u003eThe attacker interacts with the now-privileged process to spawn a root shell.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2019-13272 results in full local privilege escalation, granting an attacker complete control over the affected system. This vulnerability is highly dangerous in multi-user environments, shared hosting, or containers where local users could compromise the host or other tenants.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching Linux kernels to version 5.1.17 or later on all exposed systems. In environments where immediate kernel updates are not feasible, consider implementing the SELinux 'deny_ptrace' policy to restrict the ability of processes to trace one another, which can mitigate the exploitation vector of this vulnerability.\u003c/p\u003e\n","date_modified":"2026-08-29T23:50:09Z","date_published":"2026-08-29T23:50:09Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2019-13272/","summary":"A newly resurfaced exploit for CVE-2019-13272 allows local unprivileged users to escalate to root by abusing ptrace_link credential mishandling in the Linux kernel.","title":"Local Privilege Escalation in Linux Kernel via CVE-2019-13272","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2019-13272/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:redhat:enterprise_linux_for_real_time:8:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}