{"id":"SUSE-SU-2026:3505-1","summary":"Security update for pcp","details":"This update for pcp fixes the following issues:\n\n- CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922).\n- CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials\n  (bsc#1272923).\n- CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924).\n- CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925).\n- CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926).\n- CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927).\n- Command injection in `pmieconf` `write_pmiefile` via `$HOME` and `-f` (bsc#1272928).\n- Command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames (bsc#1272930).\n","modified":"2026-08-06T11:15:06.524531431Z","published":"2026-08-05T13:18:40Z","related":["CVE-2026-16524","CVE-2026-16526","CVE-2026-16527","CVE-2026-16529","CVE-2026-16530","CVE-2026-16531"],"upstream":["CVE-2026-16524","CVE-2026-16526","CVE-2026-16527","CVE-2026-16529","CVE-2026-16530","CVE-2026-16531"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263505-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272922"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272923"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272924"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272925"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272926"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272927"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272928"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272930"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16524"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16526"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16527"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16529"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16530"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16531"}],"affected":[{"package":{"name":"pcp","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/pcp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.0-150500.8.9.1"}]}],"ecosystem_specific":{"binaries":[{"perl-PCP-MMV":"6.2.0-150500.8.9.1","perl-PCP-LogSummary":"6.2.0-150500.8.9.1","libpcp_gui2":"6.2.0-150500.8.9.1","pcp-import-sar2pcp":"6.2.0-150500.8.9.1","libpcp_mmv1":"6.2.0-150500.8.9.1","pcp-doc":"6.2.0-150500.8.9.1","pcp-conf":"6.2.0-150500.8.9.1","perl-PCP-PMDA":"6.2.0-150500.8.9.1","libpcp_web1":"6.2.0-150500.8.9.1","libpcp3":"6.2.0-150500.8.9.1","pcp-import-mrtg2pcp":"6.2.0-150500.8.9.1","libpcp_import1":"6.2.0-150500.8.9.1","pcp":"6.2.0-150500.8.9.1","perl-PCP-LogImport":"6.2.0-150500.8.9.1","pcp-devel":"6.2.0-150500.8.9.1","libpcp_trace2":"6.2.0-150500.8.9.1","libpcp-devel":"6.2.0-150500.8.9.1","pcp-import-iostat2pcp":"6.2.0-150500.8.9.1","python3-pcp":"6.2.0-150500.8.9.1","pcp-system-tools":"6.2.0-150500.8.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3505-1.json"}},{"package":{"name":"pcp","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/pcp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.0-150500.8.9.1"}]}],"ecosystem_specific":{"binaries":[{"pcp-import-sar2pcp":"6.2.0-150500.8.9.1","pcp-devel":"6.2.0-150500.8.9.1","libpcp3":"6.2.0-150500.8.9.1","libpcp_mmv1":"6.2.0-150500.8.9.1","libpcp-devel":"6.2.0-150500.8.9.1","pcp-system-tools":"6.2.0-150500.8.9.1","libpcp_gui2":"6.2.0-150500.8.9.1","libpcp_trace2":"6.2.0-150500.8.9.1","pcp-import-mrtg2pcp":"6.2.0-150500.8.9.1","perl-PCP-LogImport":"6.2.0-150500.8.9.1","pcp-import-iostat2pcp":"6.2.0-150500.8.9.1","perl-PCP-MMV":"6.2.0-150500.8.9.1","perl-PCP-PMDA":"6.2.0-150500.8.9.1","pcp-doc":"6.2.0-150500.8.9.1","perl-PCP-LogSummary":"6.2.0-150500.8.9.1","pcp":"6.2.0-150500.8.9.1","python3-pcp":"6.2.0-150500.8.9.1","pcp-conf":"6.2.0-150500.8.9.1","libpcp_web1":"6.2.0-150500.8.9.1","libpcp_import1":"6.2.0-150500.8.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3505-1.json"}},{"package":{"name":"pcp","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/pcp&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.0-150500.8.9.1"}]}],"ecosystem_specific":{"binaries":[{"python3-pcp":"6.2.0-150500.8.9.1","pcp-doc":"6.2.0-150500.8.9.1","pcp-devel":"6.2.0-150500.8.9.1","libpcp_import1":"6.2.0-150500.8.9.1","pcp-import-iostat2pcp":"6.2.0-150500.8.9.1","perl-PCP-LogImport":"6.2.0-150500.8.9.1","libpcp-devel":"6.2.0-150500.8.9.1","pcp-conf":"6.2.0-150500.8.9.1","pcp-import-mrtg2pcp":"6.2.0-150500.8.9.1","pcp-pmda-perfevent":"6.2.0-150500.8.9.1","pcp-import-sar2pcp":"6.2.0-150500.8.9.1","perl-PCP-PMDA":"6.2.0-150500.8.9.1","libpcp3":"6.2.0-150500.8.9.1","libpcp_mmv1":"6.2.0-150500.8.9.1","pcp-system-tools":"6.2.0-150500.8.9.1","perl-PCP-LogSummary":"6.2.0-150500.8.9.1","libpcp_web1":"6.2.0-150500.8.9.1","perl-PCP-MMV":"6.2.0-150500.8.9.1","libpcp_trace2":"6.2.0-150500.8.9.1","pcp":"6.2.0-150500.8.9.1","libpcp_gui2":"6.2.0-150500.8.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3505-1.json"}},{"package":{"name":"pcp","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/pcp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.0-150500.8.9.1"}]}],"ecosystem_specific":{"binaries":[{"libpcp_import1":"6.2.0-150500.8.9.1","pcp-import-iostat2pcp":"6.2.0-150500.8.9.1","pcp":"6.2.0-150500.8.9.1","libpcp_web1":"6.2.0-150500.8.9.1","perl-PCP-PMDA":"6.2.0-150500.8.9.1","pcp-doc":"6.2.0-150500.8.9.1","python3-pcp":"6.2.0-150500.8.9.1","pcp-conf":"6.2.0-150500.8.9.1","pcp-pmda-perfevent":"6.2.0-150500.8.9.1","pcp-import-sar2pcp":"6.2.0-150500.8.9.1","perl-PCP-LogImport":"6.2.0-150500.8.9.1","pcp-import-mrtg2pcp":"6.2.0-150500.8.9.1","libpcp3":"6.2.0-150500.8.9.1","libpcp-devel":"6.2.0-150500.8.9.1","libpcp_gui2":"6.2.0-150500.8.9.1","perl-PCP-MMV":"6.2.0-150500.8.9.1","libpcp_mmv1":"6.2.0-150500.8.9.1","libpcp_trace2":"6.2.0-150500.8.9.1","pcp-system-tools":"6.2.0-150500.8.9.1","pcp-devel":"6.2.0-150500.8.9.1","perl-PCP-LogSummary":"6.2.0-150500.8.9.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3505-1.json"}}],"schema_version":"1.8.0"}