Source: pcp Version: 7.1.5-1 Severity: grave Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for pcp. Unfortunately at time of writing/filling this bugreport there were only the Red Hat bugzilla entries available (linked in the security-tracker). Do you know moe, are those fixed in 7.2.0? (The CVE ids are neither listed there). CVE-2026-16524[0]: | A command injection flaw in PCP's linux_sockets PMDA allows | malicious shell metacharacters via the network.persocket.filter | metric. This failed validation lets attackers execute arbitrary | commands as the PMDA user when metrics refresh. CVE-2026-16526[1]: | A flaw in the PCP linux_sockets module exposes an unsecured internal | connection. An attacker with initial code execution can exploit this | to escalate privileges and execute arbitrary commands as root. CVE-2026-16527[2]: | An unauthenticated remote attacker can bypass access controls by | sending crafted requests to the PCP pmproxy /store endpoint. This | allows the attacker to overwrite any PMDA metric, leading to | arbitrary code execution and system takeover. CVE-2026-16529[3]: | A signed integer overflow in the PCP __pmGetPDU() function can be | exploited via crafted network packets during PDU processing or SASL | negotiation. This permanently blinds the affected daemon, resulting | in a total denial of service (DoS) for subsequent packet reads. CVE-2026-16530[4]: | A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` | service. A remote attacker can exploit a vulnerability in the | `pmLogLoadInDom()` function by sending a specially crafted request. | This bypasses a critical bounds check, which can lead to the | `pmproxy` service crashing, causing a Denial of Service (DoS). | Additionally, this flaw may enable the leakage of sensitive | information from the system's memory. CVE-2026-16531[5]: | An unauthenticated remote attacker can exploit a path traversal | vulnerability in the PCP pmproxy logger servlet using a crafted | hostname. This allows arbitrary file and directory creation, | potentially leading to a denial of service. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-16524 https://www.cve.org/CVERecord?id=CVE-2026-16524 [1] https://security-tracker.debian.org/tracker/CVE-2026-16526 https://www.cve.org/CVERecord?id=CVE-2026-16526 [2] https://security-tracker.debian.org/tracker/CVE-2026-16527 https://www.cve.org/CVERecord?id=CVE-2026-16527 [3] https://security-tracker.debian.org/tracker/CVE-2026-16529 https://www.cve.org/CVERecord?id=CVE-2026-16529 [4] https://security-tracker.debian.org/tracker/CVE-2026-16530 https://www.cve.org/CVERecord?id=CVE-2026-16530 [5] https://security-tracker.debian.org/tracker/CVE-2026-16531 https://www.cve.org/CVERecord?id=CVE-2026-16531 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

