Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3506-1

Опубликовано: 05 авг. 2026
Источник: suse-cvrf

Описание

Security update for pcp

This update for pcp fixes the following issues:

  • CVE-2026-16524: command injection in linux_sockets PMDA via network.persocket.filter (bsc#1272922).
  • CVE-2026-16526: pmdaroot privilege escalation via FD_CLOEXEC fd inheritance and missing peer credentials (bsc#1272923).
  • CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924).
  • CVE-2026-16529: integer overflow in __pmGetPDU leads to permanent DoS (bsc#1272925).
  • CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926).
  • CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927).
  • command injection in pmieconf write_pmiefile via $HOME and -f (bsc#1272928).
  • command injection in pmlogcp/pmlogmv do_link via unsanitised filenames (bsc#1272930).

Список пакетов

SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
libpcp-devel-6.2.0-150400.5.15.1
libpcp3-6.2.0-150400.5.15.1
libpcp_gui2-6.2.0-150400.5.15.1
libpcp_import1-6.2.0-150400.5.15.1
libpcp_mmv1-6.2.0-150400.5.15.1
libpcp_trace2-6.2.0-150400.5.15.1
libpcp_web1-6.2.0-150400.5.15.1
pcp-6.2.0-150400.5.15.1
pcp-conf-6.2.0-150400.5.15.1
pcp-devel-6.2.0-150400.5.15.1
pcp-doc-6.2.0-150400.5.15.1
pcp-import-iostat2pcp-6.2.0-150400.5.15.1
pcp-import-mrtg2pcp-6.2.0-150400.5.15.1
pcp-import-sar2pcp-6.2.0-150400.5.15.1
pcp-system-tools-6.2.0-150400.5.15.1
perl-PCP-LogImport-6.2.0-150400.5.15.1
perl-PCP-LogSummary-6.2.0-150400.5.15.1
perl-PCP-MMV-6.2.0-150400.5.15.1
perl-PCP-PMDA-6.2.0-150400.5.15.1
python3-pcp-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
libpcp-devel-6.2.0-150400.5.15.1
libpcp3-6.2.0-150400.5.15.1
libpcp_gui2-6.2.0-150400.5.15.1
libpcp_import1-6.2.0-150400.5.15.1
libpcp_mmv1-6.2.0-150400.5.15.1
libpcp_trace2-6.2.0-150400.5.15.1
libpcp_web1-6.2.0-150400.5.15.1
pcp-6.2.0-150400.5.15.1
pcp-conf-6.2.0-150400.5.15.1
pcp-devel-6.2.0-150400.5.15.1
pcp-doc-6.2.0-150400.5.15.1
pcp-import-iostat2pcp-6.2.0-150400.5.15.1
pcp-import-mrtg2pcp-6.2.0-150400.5.15.1
pcp-import-sar2pcp-6.2.0-150400.5.15.1
pcp-system-tools-6.2.0-150400.5.15.1
perl-PCP-LogImport-6.2.0-150400.5.15.1
perl-PCP-LogSummary-6.2.0-150400.5.15.1
perl-PCP-MMV-6.2.0-150400.5.15.1
perl-PCP-PMDA-6.2.0-150400.5.15.1
python3-pcp-6.2.0-150400.5.15.1
SUSE Linux Enterprise Server 15 SP4-LTSS
libpcp-devel-6.2.0-150400.5.15.1
libpcp3-6.2.0-150400.5.15.1
libpcp_gui2-6.2.0-150400.5.15.1
libpcp_import1-6.2.0-150400.5.15.1
libpcp_mmv1-6.2.0-150400.5.15.1
libpcp_trace2-6.2.0-150400.5.15.1
libpcp_web1-6.2.0-150400.5.15.1
pcp-6.2.0-150400.5.15.1
pcp-conf-6.2.0-150400.5.15.1
pcp-devel-6.2.0-150400.5.15.1
pcp-doc-6.2.0-150400.5.15.1
pcp-import-iostat2pcp-6.2.0-150400.5.15.1
pcp-import-mrtg2pcp-6.2.0-150400.5.15.1
pcp-import-sar2pcp-6.2.0-150400.5.15.1
pcp-pmda-perfevent-6.2.0-150400.5.15.1
pcp-system-tools-6.2.0-150400.5.15.1
perl-PCP-LogImport-6.2.0-150400.5.15.1
perl-PCP-LogSummary-6.2.0-150400.5.15.1
perl-PCP-MMV-6.2.0-150400.5.15.1
perl-PCP-PMDA-6.2.0-150400.5.15.1
python3-pcp-6.2.0-150400.5.15.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
libpcp-devel-6.2.0-150400.5.15.1
libpcp3-6.2.0-150400.5.15.1
libpcp_gui2-6.2.0-150400.5.15.1
libpcp_import1-6.2.0-150400.5.15.1
libpcp_mmv1-6.2.0-150400.5.15.1
libpcp_trace2-6.2.0-150400.5.15.1
libpcp_web1-6.2.0-150400.5.15.1
pcp-6.2.0-150400.5.15.1
pcp-conf-6.2.0-150400.5.15.1
pcp-devel-6.2.0-150400.5.15.1
pcp-doc-6.2.0-150400.5.15.1
pcp-import-iostat2pcp-6.2.0-150400.5.15.1
pcp-import-mrtg2pcp-6.2.0-150400.5.15.1
pcp-import-sar2pcp-6.2.0-150400.5.15.1
pcp-pmda-perfevent-6.2.0-150400.5.15.1
pcp-system-tools-6.2.0-150400.5.15.1
perl-PCP-LogImport-6.2.0-150400.5.15.1
perl-PCP-LogSummary-6.2.0-150400.5.15.1
perl-PCP-MMV-6.2.0-150400.5.15.1
perl-PCP-PMDA-6.2.0-150400.5.15.1
python3-pcp-6.2.0-150400.5.15.1

Описание

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp-devel-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp3-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp_gui2-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp_import1-6.2.0-150400.5.15.1

Ссылки

Описание

A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp-devel-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp3-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp_gui2-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp_import1-6.2.0-150400.5.15.1

Ссылки

Описание

An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp-devel-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp3-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp_gui2-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp_import1-6.2.0-150400.5.15.1

Ссылки

Описание

A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp-devel-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp3-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp_gui2-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp_import1-6.2.0-150400.5.15.1

Ссылки

Описание

A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp-devel-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp3-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp_gui2-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp_import1-6.2.0-150400.5.15.1

Ссылки

Описание

An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp-devel-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp3-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp_gui2-6.2.0-150400.5.15.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:libpcp_import1-6.2.0-150400.5.15.1

Ссылки
Уязвимость SUSE-SU-2026:3506-1