Source: pcp
Version: 7.1.5-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for pcp.

Unfortunately at time of writing/filling this bugreport there were
only the Red Hat bugzilla entries available (linked in the
security-tracker). Do you know moe, are those fixed in 7.2.0? (The CVE
ids are neither listed there).

CVE-2026-16524[0]:
| A command injection flaw in PCP's linux_sockets PMDA allows
| malicious shell metacharacters via the network.persocket.filter
| metric. This failed validation lets attackers execute arbitrary
| commands as the PMDA user when metrics refresh.


CVE-2026-16526[1]:
| A flaw in the PCP linux_sockets module exposes an unsecured internal
| connection. An attacker with initial code execution can exploit this
| to escalate privileges and execute arbitrary commands as root.


CVE-2026-16527[2]:
| An unauthenticated remote attacker can bypass access controls by
| sending crafted requests to the PCP pmproxy /store endpoint. This
| allows the attacker to overwrite any PMDA metric, leading to
| arbitrary code execution and system takeover.


CVE-2026-16529[3]:
| A signed integer overflow in the PCP __pmGetPDU() function can be
| exploited via crafted network packets during PDU processing or SASL
| negotiation. This permanently blinds the affected daemon, resulting
| in a total denial of service (DoS) for subsequent packet reads.


CVE-2026-16530[4]:
| A flaw was found in the PCP (Performance Co-Pilot) `pmproxy`
| service. A remote attacker can exploit a vulnerability in the
| `pmLogLoadInDom()` function by sending a specially crafted request.
| This bypasses a critical bounds check, which can lead to the
| `pmproxy` service crashing, causing a Denial of Service (DoS).
| Additionally, this flaw may enable the leakage of sensitive
| information from the system's memory.


CVE-2026-16531[5]:
| An unauthenticated remote attacker can exploit a path traversal
| vulnerability in the PCP pmproxy logger servlet using a crafted
| hostname. This allows arbitrary file and directory creation,
| potentially leading to a denial of service.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-16524
    https://www.cve.org/CVERecord?id=CVE-2026-16524
[1] https://security-tracker.debian.org/tracker/CVE-2026-16526
    https://www.cve.org/CVERecord?id=CVE-2026-16526
[2] https://security-tracker.debian.org/tracker/CVE-2026-16527
    https://www.cve.org/CVERecord?id=CVE-2026-16527
[3] https://security-tracker.debian.org/tracker/CVE-2026-16529
    https://www.cve.org/CVERecord?id=CVE-2026-16529
[4] https://security-tracker.debian.org/tracker/CVE-2026-16530
    https://www.cve.org/CVERecord?id=CVE-2026-16530
[5] https://security-tracker.debian.org/tracker/CVE-2026-16531
    https://www.cve.org/CVERecord?id=CVE-2026-16531

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to