{"id":"SUSE-SU-2026:23174-1","summary":"Security update for pcp","details":"This update for pcp fixes the following issues:\n\n- CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922).\n- CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials\n  (bsc#1272923).\n- CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924).\n- CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925).\n- CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926).\n- CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927).\n- command injection in `pmieconf` `write_pmiefile` via `$HOME` and `-f` (bsc#1272928).\n- command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames (bsc#1272930).\n","modified":"2026-08-22T18:23:33.714116369Z","published":"2026-08-11T11:26:25Z","related":["CVE-2026-16524","CVE-2026-16526","CVE-2026-16527","CVE-2026-16529","CVE-2026-16530","CVE-2026-16531"],"upstream":["CVE-2026-16524","CVE-2026-16526","CVE-2026-16527","CVE-2026-16529","CVE-2026-16530","CVE-2026-16531"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623174-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272922"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272923"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272924"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272925"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272926"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272927"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272928"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272930"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16524"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16526"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16527"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16529"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16530"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16531"}],"affected":[{"package":{"name":"pcp","ecosystem":"SUSE:Linux Micro 6.1","purl":"pkg:rpm/suse/pcp&distro=SUSE%20Linux%20Micro%206.1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.0-slfo.1.1_6.1"}]}],"ecosystem_specific":{"binaries":[{"libpcp3":"6.2.0-slfo.1.1_6.1","libpcp_import1":"6.2.0-slfo.1.1_6.1","pcp-conf":"6.2.0-slfo.1.1_6.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23174-1.json"}}],"schema_version":"1.9.0"}