CISA KEV · catalog date Dec 10, 2021 · first observed Jul 19, 2026
Evidence dossier
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which…
Exploited in the wild (CISA KEV since Dec 10, 2021). NVD reports CVSS 3.1 7.8. EPSS estimates 52.2% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
- State
- PUBLISHED
- Published
- Jul 17, 2019
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmitreOriginal evidence ↗
Record text: In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
Inspect raw assertion
- Field
container- Value
- In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Linux Kernel Improper Privilege Management Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Improper Privilege Management Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 52.2% probability · 98.87th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.521990000000; percentile 0.988720000000
FIRST EPSS · score date Aug 26, 2026 · 98.9th percentile · first observed Aug 26, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
Inspect raw assertion
- Field
container- Value
- In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
Linux Kernel Improper Privilege Management Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Improper Privilege Management Vulnerability
52.2% probability · 98.87th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.521990000000; percentile 0.988720000000
Applicability
Cited product scope
Grouped from 12 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
26 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exactInspect raw assertions
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a5301bf-1402-4be0-a0f8-69fbe79bc6d6
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cd783b0c-9246-47d9-a937-6144fe8bff0f
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b3293e55-5506-4587-a318-d1734f781c09
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertions
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
deece5fc-cacf-4496-a3e7-164736409252
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
07b237a9-69a3-4a9c-9da0-4e06bd37ae73
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c11e6fb0-c8c0-4527-9aa0-cb9b316f8f43
product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exactInspect raw assertion
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d100f7ce-fc64-4cc6-852a-6136d72da419
product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9Linked exactInspect raw assertions
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 4.1.39; through excluding 4.2
- Match ID
cd709672-0e6a-4086-8700-b6c2fdd8599c
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- from including 4.9.1; through excluding 4.9.185
- Match ID
8a719867-aeb7-4e95-a1de-b96ea092d9fe
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- from including 4.10; through excluding 4.14.133
- Match ID
00d95a2f-5b17-46d9-80d7-2e0d1779c2ce
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- from including 4.20; through excluding 5.1.17
- Match ID
7049e422-0d4b-45fd-8b06-04bacd44a66e
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- from including 4.15; through excluding 4.19.58
- Match ID
f921620b-e2a7-421f-8c89-016c51723c17
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 4.8.16; through excluding 4.9
- Match ID
66431ba1-01b5-476a-b483-ae4e7b830ba7
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 3.16.52; through excluding 3.16.71
- Match ID
aa88b130-cd8a-4e14-a1f5-4d1db031d60e
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 4.4.40; through excluding 4.4.185
- Match ID
19fb5fc5-740b-418f-b83a-3ea6095270c0
product-7622e4e001e04d07e68c37d95f4e8879bc2e631632b5d522e6504407a3f05f79Linked exactInspect raw assertion
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3a756737-1cc4-42c2-a4df-e1c893b4e2d5
product-c919ba8b0dd8e968c19b8e77cdf88d19089dcc30a0dd28a78aa2ef42e4d9ac0eLinked exactInspect raw assertion
cpe:2.3:h:netapp:aff_a700s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 5 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9fed1b0d-f901-413a-85d9-05d4c427570d
product-0b1081eec5c2cec449156e363579ec881bdaa3fd2a25b442704ff6a7d63f8302Linked exactInspect raw assertion
cpe:2.3:o:netapp:aff_a700s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
952f55c9-7e7c-4539-9d08-e736b3488569
product-225285266271e574f710d85b0b88f3d70ee572ac60343ac3478b9cce08c99983Linked exactInspect raw assertion
cpe:2.3:a:netapp:e-series_performance_analyzer:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
24b8db06-590a-4008-b0ab-fcd1401c77c6
product-300c410d26e89b303b330d1a01b969a22d1c9a67623afee0f8b4b2aaf28f7524Linked exactInspect raw assertion
cpe:2.3:a:netapp:e-series_santricity_os_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 11.0.0; through including 11.60.3
- Match ID
bd1e9594-c46f-40d1-8bc2-6b16635b55c4
product-19a4460172d592ee30b338581dced13baf393eedf54989f7303c0971a7aa6832Linked exactInspect raw assertion
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cddf61b7-ec5c-467c-b710-b89f502cd04f
product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045aLinked exactInspect raw assertion
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
234defe0-5ce5-4b0a-96b8-5d227cb8ed31
product-3957199dfb29d702382dde1506ec753a2e995f2a797bfa3f56758eba63ced183Linked exactInspect raw assertion
cpe:2.3:h:netapp:h610s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f63a3fa7-aaed-4a9d-9fde-6195302da0f6
product-ce5a951956802b54eda64165939e5e2c5df7ce5a73bad036b8ea9a7eb7fd5eedLinked exactInspect raw assertion
cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fd7cfe0e-9d1e-4495-b302-89c3096fc0df
product-ac128f79df6958432aba953aa4fde55d70b2ccbfc258439c013b541010526631Linked exactInspect raw assertion
cpe:2.3:h:netapp:hci_compute_node:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ad7447bc-f315-4298-a822-549942fc118b
product-b96bd9c5f25fe809238d4145773458d6ff936886a379c046bfbe8070415bf846Linked exactInspect raw assertion
cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a3c19813-e823-456a-b1ce-ec0684ce1953
product-2a92f5fffc7d95c283c9b431fb9d893507d0fd3d5e5c17bf17e1f6e198053729Linked exactInspect raw assertion
cpe:2.3:a:netapp:service_processor:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
146a767f-dc04-454b-9913-17d3a2b5aaa4
product-3f0c13ae987268d938a748a6775a56a1c59c577b908d80ca86854083f202c4a8Linked exactInspect raw assertion
cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a6e9ef0c-afa8-4f7b-9fdc-1e0f7c26e737
product-24d50f5fd6a6b808539d86c8d5a22c388f6aacd86e50e6f3646ceac0f166e3deLinked exactInspect raw assertion
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e94f7f59-1785-493f-91a7-5f5ea5e87e4d
product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844eeLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
142ad0dd-4cf3-4d74-9442-459ce3347e3a
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f4cff558-3c47-480d-a2f0-babf26042943
product-5b647cbf10edba654fbfb5f3617b5887cae2cdbd5242317dd9286e31cb74c078Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_arm_64:7.0_aarch64:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
aa559d29-df65-48af-96db-d20a50474758
product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0bLinked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_ibm_z_systems:7.0_s390x:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2148300c-ecbd-4ed5-a164-79629859dd43
product-901d9f9538a92b46f20476f4fb53a96f70e1a61e84c741649d26cdd496518787Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_real_time:8:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cbf9bcf3-187f-410a-96ca-9c47d3ed6924
product-738247a33e0b2793bee8362c6479c59f0d87c85245210ea2dac5d06050406427Linked exactInspect raw assertion
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
782c86cd-1b68-410a-a096-e5170ad24da2
product-d77cc1a1fefec2e8775cda418005f8915bf7c83bb7052bf25df4ce37b5cf7cceLinked exactInspect raw assertions
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6d5de3c5-b090-4ce7-9af2-deb379d7d5fc
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.8:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
df7275a1-8853-469e-939b-7533e9e8c499
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
77c61ddc-81f3-4e2d-9caa-17a256c85443
cpe:2.3:o:redhat:enterprise_linux_for_real_time_for_nfv_tus:8.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b6b0da79-df12-4418-b075-f048c9e2979a
Affected-product evidence
Accepted scope and product mapping
22 canonical links · 1 source-reported links
vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-0b1081eec5c2cec449156e363579ec881bdaa3fd2a25b442704ff6a7d63f8302
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fcd86d5c-c583-4f46-9a9c-1410a75f49e2vendor-9c702362a97e8770255c53f324861f65f3209d35ce95f01842c69a458450f6fa · product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 8
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
388d8027-0f68-4f06-ac7d-f4138c422db78f039305-3845-4b53-ac65-14769e4813e7aedd41b9-aa87-4af7-bfae-32da25ad3c4bb4af7275-3f2f-4936-af77-0d0e5d0ceb76ca505a07-a91b-4905-8efd-4982196cf590cd3a5b5e-14ac-4093-9d0e-1b9dd8f9f643e2b1f7b1-2d0e-430f-91af-3c2545899f7cf1481eea-29ca-4ed9-891c-32641238b769vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-225285266271e574f710d85b0b88f3d70ee572ac60343ac3478b9cce08c99983
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
11b629ce-af2e-451a-a71e-f90ae187124evendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-24d50f5fd6a6b808539d86c8d5a22c388f6aacd86e50e6f3646ceac0f166e3de
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b1ed8b6e-c88c-4369-8628-81f8be10da02vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-2a92f5fffc7d95c283c9b431fb9d893507d0fd3d5e5c17bf17e1f6e198053729
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
47af9612-576a-41f2-80ec-7e79f005ff98vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-300c410d26e89b303b330d1a01b969a22d1c9a67623afee0f8b4b2aaf28f7524
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
cbc90c14-fe6c-4da7-8147-b2ddf22a2f27vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
06455622-5f9b-4163-b465-cde3fed98d712e048439-6f0e-4596-bbf0-01c6ab5cd031d7fb5058-52be-4e27-aca3-27578496c1a9vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fceb4a43-5d4c-4881-81ad-cdef456cd67cvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3f0c13ae987268d938a748a6775a56a1c59c577b908d80ca86854083f202c4a8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
46b2ee67-39e7-4580-9282-fbabfa17ebb6vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-47dee1744bced301ddbc92cf5cc13b521975487b8f5b36604aaffd87a1ae790b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0d0ed744-43ab-454a-ba22-486d7916f8067d792445-490f-4550-bace-26178e20612194483476-98e4-4bf0-b879-3e141620d23299306a23-6021-45ad-b721-6e78bd831371vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-5b647cbf10edba654fbfb5f3617b5887cae2cdbd5242317dd9286e31cb74c078
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ea0f6e1d-2baf-4c43-ae49-8ae559561672vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-738247a33e0b2793bee8362c6479c59f0d87c85245210ea2dac5d06050406427
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f4c62a9b-6312-49ad-bf5a-f15d265ed2d0vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-7622e4e001e04d07e68c37d95f4e8879bc2e631632b5d522e6504407a3f05f79
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d43ea371-a354-4ef0-9c32-a3197e460373vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-901d9f9538a92b46f20476f4fb53a96f70e1a61e84c741649d26cdd496518787
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5a95c6b8-1840-4268-b895-071e65e8ef57vendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4ed23edf-d50e-40fd-a4be-a298af8dd220c917db05-fbb1-429e-a80e-36f58fe0ce87d7fd6e3c-1461-4b26-993f-b62365b55407vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-ac128f79df6958432aba953aa4fde55d70b2ccbfc258439c013b541010526631
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
43c17578-7aa1-48cc-b718-81b921671063vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-b96bd9c5f25fe809238d4145773458d6ff936886a379c046bfbe8070415bf846
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3edd6a69-a929-446d-ac21-6df1205d8980vendor-2d566b06907460b10e6e48c8544126e19f1d6df137983056edae8d0b51e34e45 · product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d3de904c-ecef-4333-8e5b-43d8279630b6vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-ce5a951956802b54eda64165939e5e2c5df7ce5a73bad036b8ea9a7eb7fd5eed
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
86dc56d9-d904-4c28-935e-fccaa2236f76vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d77cc1a1fefec2e8775cda418005f8915bf7c83bb7052bf25df4ce37b5cf7cce
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
536b96ef-f27b-4b09-b174-0f08671e95876825b418-2223-4995-ab2d-43ddd4c1baef6d42b9ff-e81e-4d8c-a4ab-5346ace291d78822dd34-a864-42f9-84ce-194ddf3b9dbbvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844ee
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9129737f-2d12-4e75-9e07-67a6a7b32711f444efa3-08fa-4c25-85f2-54dbadb2813evendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5b6e25bd-39e4-43a6-86ae-25a4d7acad63Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5f9ffe3d-dccf-48db-9471-8bbed2461088Assessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAV:L/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 7.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.