{"id":"SUSE-SU-2026:3507-1","summary":"Security update for pcp","details":"This update for pcp fixes the following issues:\n\n- CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922).\n- CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials\n  (bsc#1272923).\n- CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924).\n- CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925).\n- CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926).\n- CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927).\n- command injection in `pmieconf` `write_pmiefile` via `$HOME` and `-f` (bsc#1272928).\n- command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames (bsc#1272930).\n","modified":"2026-08-06T11:15:06.521730808Z","published":"2026-08-05T13:20:36Z","related":["CVE-2026-16524","CVE-2026-16526","CVE-2026-16527","CVE-2026-16529","CVE-2026-16530","CVE-2026-16531"],"upstream":["CVE-2026-16524","CVE-2026-16526","CVE-2026-16527","CVE-2026-16529","CVE-2026-16530","CVE-2026-16531"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263507-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272922"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272923"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272924"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272925"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272926"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272927"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272928"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272930"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16524"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16526"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16527"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16529"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16530"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-16531"}],"affected":[{"package":{"name":"pcp","ecosystem":"SUSE:Linux Enterprise Module for Development Tools 15 SP7","purl":"pkg:rpm/suse/pcp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.0-150600.3.12.1"}]}],"ecosystem_specific":{"binaries":[{"libpcp_web1":"6.2.0-150600.3.12.1","libpcp_gui2":"6.2.0-150600.3.12.1","libpcp3":"6.2.0-150600.3.12.1","pcp-system-tools":"6.2.0-150600.3.12.1","pcp-import-sar2pcp":"6.2.0-150600.3.12.1","pcp-import-iostat2pcp":"6.2.0-150600.3.12.1","perl-PCP-MMV":"6.2.0-150600.3.12.1","pcp-import-mrtg2pcp":"6.2.0-150600.3.12.1","perl-PCP-PMDA":"6.2.0-150600.3.12.1","pcp-doc":"6.2.0-150600.3.12.1","pcp-conf":"6.2.0-150600.3.12.1","pcp":"6.2.0-150600.3.12.1","libpcp-devel":"6.2.0-150600.3.12.1","pcp-pmda-perfevent":"6.2.0-150600.3.12.1","libpcp_trace2":"6.2.0-150600.3.12.1","perl-PCP-LogSummary":"6.2.0-150600.3.12.1","libpcp_mmv1":"6.2.0-150600.3.12.1","pcp-devel":"6.2.0-150600.3.12.1","perl-PCP-LogImport":"6.2.0-150600.3.12.1","python3-pcp":"6.2.0-150600.3.12.1","libpcp_import1":"6.2.0-150600.3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3507-1.json"}},{"package":{"name":"pcp","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/pcp&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.0-150600.3.12.1"}]}],"ecosystem_specific":{"binaries":[{"libpcp3":"6.2.0-150600.3.12.1","libpcp_trace2":"6.2.0-150600.3.12.1","perl-PCP-MMV":"6.2.0-150600.3.12.1","pcp":"6.2.0-150600.3.12.1","libpcp_mmv1":"6.2.0-150600.3.12.1","libpcp_web1":"6.2.0-150600.3.12.1","pcp-import-iostat2pcp":"6.2.0-150600.3.12.1","python3-pcp":"6.2.0-150600.3.12.1","pcp-system-tools":"6.2.0-150600.3.12.1","perl-PCP-LogSummary":"6.2.0-150600.3.12.1","libpcp_gui2":"6.2.0-150600.3.12.1","libpcp_import1":"6.2.0-150600.3.12.1","perl-PCP-PMDA":"6.2.0-150600.3.12.1","pcp-doc":"6.2.0-150600.3.12.1","pcp-import-sar2pcp":"6.2.0-150600.3.12.1","pcp-import-mrtg2pcp":"6.2.0-150600.3.12.1","pcp-conf":"6.2.0-150600.3.12.1","pcp-pmda-perfevent":"6.2.0-150600.3.12.1","perl-PCP-LogImport":"6.2.0-150600.3.12.1","pcp-devel":"6.2.0-150600.3.12.1","libpcp-devel":"6.2.0-150600.3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3507-1.json"}},{"package":{"name":"pcp","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/pcp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.2.0-150600.3.12.1"}]}],"ecosystem_specific":{"binaries":[{"pcp":"6.2.0-150600.3.12.1","libpcp-devel":"6.2.0-150600.3.12.1","pcp-system-tools":"6.2.0-150600.3.12.1","libpcp_mmv1":"6.2.0-150600.3.12.1","libpcp_import1":"6.2.0-150600.3.12.1","perl-PCP-PMDA":"6.2.0-150600.3.12.1","pcp-import-mrtg2pcp":"6.2.0-150600.3.12.1","pcp-import-sar2pcp":"6.2.0-150600.3.12.1","pcp-import-iostat2pcp":"6.2.0-150600.3.12.1","pcp-conf":"6.2.0-150600.3.12.1","libpcp_trace2":"6.2.0-150600.3.12.1","python3-pcp":"6.2.0-150600.3.12.1","perl-PCP-LogSummary":"6.2.0-150600.3.12.1","libpcp_web1":"6.2.0-150600.3.12.1","pcp-doc":"6.2.0-150600.3.12.1","libpcp3":"6.2.0-150600.3.12.1","perl-PCP-LogImport":"6.2.0-150600.3.12.1","perl-PCP-MMV":"6.2.0-150600.3.12.1","pcp-pmda-perfevent":"6.2.0-150600.3.12.1","libpcp_gui2":"6.2.0-150600.3.12.1","pcp-devel":"6.2.0-150600.3.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3507-1.json"}}],"schema_version":"1.8.0"}