Описание
A flaw was found in the PCP (Performance Co-Pilot) pmproxy service. A remote attacker can exploit a vulnerability in the pmLogLoadInDom() function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the pmproxy service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.
Отчет
This Moderate impact flaw in the PCP pmproxy service allows a remote, unauthenticated attacker to trigger a denial of service or information leakage. The vulnerability stems from a bypassed bounds check in the pmLogLoadInDom() function, which can lead to service instability or memory exposure. Exploitation requires the pmproxy service to be reachable on its default TCP port 44322.
Меры по смягчению последствий
To mitigate this issue, restrict network access to the pmproxy service on TCP port 44322 using firewall rules. Alternatively, if the pmproxy service is not required, it can be disabled to prevent exploitation.
Example to disable pmproxy:
sudo systemctl stop pmproxy
sudo systemctl disable pmproxy
Note that disabling pmproxy may impact functionality that relies on it. A service reload or restart may be required for changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | pcp | Affected | ||
| Red Hat Enterprise Linux 6 | pcp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | pcp | Out of support scope | ||
| Red Hat Enterprise Linux 8 | pcp | Fix deferred | ||
| Red Hat Enterprise Linux 9 | pcp | Affected | ||
| Red Hat OpenShift Container Platform 4 | rhcos | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.
A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.
A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. ...
A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.
EPSS
6.5 Medium
CVSS3