Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16524

Опубликовано: 30 июл. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

Отчет

This flaw is rated as Important because it allows a local attacker to achieve arbitrary command execution as the PMDA process user within the Performance Co-Pilot (PCP) environment. Exploitation requires the linux_sockets PMDA to be loaded and the ss utility to be present, which are common configurations. The vulnerability stems from an inverted validation logic in the sockets_check_filter() function, enabling the injection of malicious shell metacharacters into a filter value that is later executed.

Меры по смягчению последствий

To prevent exploitation, restrict access to the pmstore utility by configuring the [access] section in /etc/pcp/pmcd/pmcd.conf. If the linux_sockets PMDA is not essential, it can be unloaded or disabled to remove the attack vector. After modifying pmcd.conf, the pmcd service must be restarted for changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10pcpAffected
Red Hat Enterprise Linux 6pcpOut of support scope
Red Hat Enterprise Linux 7pcpAffected
Red Hat Enterprise Linux 8pcpAffected
Red Hat Enterprise Linux 9pcpAffected
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2506023PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection

EPSS

Процентиль: 62%
0.01077
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
19 дней назад

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

CVSS3: 7.8
nvd
19 дней назад

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

CVSS3: 7.8
debian
19 дней назад

A command injection flaw in PCP's linux_sockets PMDA allows malicious ...

CVSS3: 7.8
github
19 дней назад

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

suse-cvrf
12 дней назад

Security update for pcp

EPSS

Процентиль: 62%
0.01077
Низкий

7.8 High

CVSS3