Vulnerability Note VU#628849

ptrace contains vulnerability allowing for local root compromise

Original Release date: 16 Apr 2004 | Last revised: 30 Apr 2004


A vulnerability in the Linux 2.2 and 2.4 distributions of ptrace() may permit a local attacker to gain elevated privileges.


The Linux 2.2 and 2.4 kernels contained a flaw in ptrace(). This vulnerability may permit a local user to have the kernel spawn a child process. From the man page:

    The ptrace system call provides a means by which a parent process may observe and control the execution of another process, and examine and change its core image and registers. It is primarily used to implement breakpoint debugging and system call tracing.

If the kernel is built with modules and kernel module loader enabled and /proc/sys/kernel/modprobe contains the path to a valid executable and ptrace() calls are not blocked, then a local user may be able to exploit this vulnerability to gain root privileges to the system.

The CERT/CC has seen active exploitation of this vulnerability.


A local user can exploit this vulnerability to gain elevated privileges, typically root.


This vulnerability has been resolved in Linux 2.2.25 and 2.4.21. Various vendors have also released advisories and updates. Please see the your vendor's advisory for more details.

Systems Affected (Learn More)

VendorStatusDate NotifiedDate Updated
ConectivaAffected-16 Apr 2004
DebianAffected-16 Apr 2004
GentooAffected-16 Apr 2004
Guardian Digital Inc. Affected-16 Apr 2004
Linux Kernel ArchivesAffected-16 Apr 2004
MandrakeSoftAffected-16 Apr 2004
Red Hat Inc.Affected-16 Apr 2004
SCOAffected-16 Apr 2004
SlackwareAffected-16 Apr 2004
SuSE Inc.Affected-16 Apr 2004
TrustixAffected-16 Apr 2004
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A N/A



Thanks to Andrzej Szombierski for reporting this vulnerability.

This document was written by Jason A Rafail and is based on information provided by Andrzej Szombierski.

Other Information

  • CVE IDs: CAN-2003-0127
  • Date Public: 17 Mar 2003
  • Date First Published: 16 Apr 2004
  • Date Last Updated: 30 Apr 2004
  • Severity Metric: 14.25
  • Document Revision: 9


If you have feedback, comments, or additional information about this vulnerability, please send us email.