#1143154 pcp: CVE-2026-16524 CVE-2026-16526 CVE-2026-16527 CVE-2026-16529 CVE-2026-16530 CVE-2026-16531

Package:
src:pcp
Source:
src:pcp
Submitter:
Salvatore Bonaccorso
Date:
2026-08-25 05:49:02 UTC
Severity:
normal
Tags:
#1143154#5
Date:
2026-07-31 05:17:43 UTC
From:
To:
Hi,

The following vulnerabilities were published for pcp.

Unfortunately at time of writing/filling this bugreport there were
only the Red Hat bugzilla entries available (linked in the
security-tracker). Do you know moe, are those fixed in 7.2.0? (The CVE
ids are neither listed there).

CVE-2026-16524[0]:
| A command injection flaw in PCP's linux_sockets PMDA allows
| malicious shell metacharacters via the network.persocket.filter
| metric. This failed validation lets attackers execute arbitrary
| commands as the PMDA user when metrics refresh.


CVE-2026-16526[1]:
| A flaw in the PCP linux_sockets module exposes an unsecured internal
| connection. An attacker with initial code execution can exploit this
| to escalate privileges and execute arbitrary commands as root.


CVE-2026-16527[2]:
| An unauthenticated remote attacker can bypass access controls by
| sending crafted requests to the PCP pmproxy /store endpoint. This
| allows the attacker to overwrite any PMDA metric, leading to
| arbitrary code execution and system takeover.


CVE-2026-16529[3]:
| A signed integer overflow in the PCP __pmGetPDU() function can be
| exploited via crafted network packets during PDU processing or SASL
| negotiation. This permanently blinds the affected daemon, resulting
| in a total denial of service (DoS) for subsequent packet reads.


CVE-2026-16530[4]:
| A flaw was found in the PCP (Performance Co-Pilot) `pmproxy`
| service. A remote attacker can exploit a vulnerability in the
| `pmLogLoadInDom()` function by sending a specially crafted request.
| This bypasses a critical bounds check, which can lead to the
| `pmproxy` service crashing, causing a Denial of Service (DoS).
| Additionally, this flaw may enable the leakage of sensitive
| information from the system's memory.


CVE-2026-16531[5]:
| An unauthenticated remote attacker can exploit a path traversal
| vulnerability in the PCP pmproxy logger servlet using a crafted
| hostname. This allows arbitrary file and directory creation,
| potentially leading to a denial of service.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-16524
https://www.cve.org/CVERecord?id=CVE-2026-16524
[1] https://security-tracker.debian.org/tracker/CVE-2026-16526
https://www.cve.org/CVERecord?id=CVE-2026-16526
[2] https://security-tracker.debian.org/tracker/CVE-2026-16527
https://www.cve.org/CVERecord?id=CVE-2026-16527
[3] https://security-tracker.debian.org/tracker/CVE-2026-16529
https://www.cve.org/CVERecord?id=CVE-2026-16529
[4] https://security-tracker.debian.org/tracker/CVE-2026-16530
https://www.cve.org/CVERecord?id=CVE-2026-16530
[5] https://security-tracker.debian.org/tracker/CVE-2026-16531
https://www.cve.org/CVERecord?id=CVE-2026-16531

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1143154#10
Date:
2026-08-25 00:53:44 UTC
From:
To:
Thanks Savatore, these issues are resolved by pcp-7.2.1 currently in
testing and unstable.

#1143154#15
Date:
2026-08-25 05:46:40 UTC
From:
To:
Hi Nathan,

Thanks, will update the security-tracker. Do you have upstream
references for the individual issues? So far we were only tracking the
Red Hat bugzilla entries with the summaries, but those miss as well
upstream change references.

Regards,
Salvatore