#1143154 pcp: CVE-2026-16524 CVE-2026-16526 CVE-2026-16527 CVE-2026-16529 CVE-2026-16530 CVE-2026-16531

Package:
src:pcp
Source:
src:pcp
Submitter:
Salvatore Bonaccorso
Date:
2026-07-31 05:19:02 UTC
Severity:
normal
Tags:
#1143154#5
Date:
2026-07-31 05:17:43 UTC
From:
To:
Hi,

The following vulnerabilities were published for pcp.

Unfortunately at time of writing/filling this bugreport there were
only the Red Hat bugzilla entries available (linked in the
security-tracker). Do you know moe, are those fixed in 7.2.0? (The CVE
ids are neither listed there).

CVE-2026-16524[0]:
| A command injection flaw in PCP's linux_sockets PMDA allows
| malicious shell metacharacters via the network.persocket.filter
| metric. This failed validation lets attackers execute arbitrary
| commands as the PMDA user when metrics refresh.


CVE-2026-16526[1]:
| A flaw in the PCP linux_sockets module exposes an unsecured internal
| connection. An attacker with initial code execution can exploit this
| to escalate privileges and execute arbitrary commands as root.


CVE-2026-16527[2]:
| An unauthenticated remote attacker can bypass access controls by
| sending crafted requests to the PCP pmproxy /store endpoint. This
| allows the attacker to overwrite any PMDA metric, leading to
| arbitrary code execution and system takeover.


CVE-2026-16529[3]:
| A signed integer overflow in the PCP __pmGetPDU() function can be
| exploited via crafted network packets during PDU processing or SASL
| negotiation. This permanently blinds the affected daemon, resulting
| in a total denial of service (DoS) for subsequent packet reads.


CVE-2026-16530[4]:
| A flaw was found in the PCP (Performance Co-Pilot) `pmproxy`
| service. A remote attacker can exploit a vulnerability in the
| `pmLogLoadInDom()` function by sending a specially crafted request.
| This bypasses a critical bounds check, which can lead to the
| `pmproxy` service crashing, causing a Denial of Service (DoS).
| Additionally, this flaw may enable the leakage of sensitive
| information from the system's memory.


CVE-2026-16531[5]:
| An unauthenticated remote attacker can exploit a path traversal
| vulnerability in the PCP pmproxy logger servlet using a crafted
| hostname. This allows arbitrary file and directory creation,
| potentially leading to a denial of service.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-16524
https://www.cve.org/CVERecord?id=CVE-2026-16524
[1] https://security-tracker.debian.org/tracker/CVE-2026-16526
https://www.cve.org/CVERecord?id=CVE-2026-16526
[2] https://security-tracker.debian.org/tracker/CVE-2026-16527
https://www.cve.org/CVERecord?id=CVE-2026-16527
[3] https://security-tracker.debian.org/tracker/CVE-2026-16529
https://www.cve.org/CVERecord?id=CVE-2026-16529
[4] https://security-tracker.debian.org/tracker/CVE-2026-16530
https://www.cve.org/CVERecord?id=CVE-2026-16530
[5] https://security-tracker.debian.org/tracker/CVE-2026-16531
https://www.cve.org/CVERecord?id=CVE-2026-16531

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore