Your message dated Tue, 25 Aug 2026 10:53:44 +1000
with message-id 
<cafmei7prznprzsgefcg+6uphf3hctq8qrrx+ehk29fy6tbi...@mail.gmail.com>
and subject line pcp: CVE-2026-16524 CVE-2026-16526 CVE-2026-16527 
CVE-2026-16529 CVE-2026-16530 CVE-2026-16531
has caused the Debian Bug report #1143154,
regarding pcp: CVE-2026-16524 CVE-2026-16526 CVE-2026-16527 CVE-2026-16529 
CVE-2026-16530 CVE-2026-16531
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1143154: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143154
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: pcp
Version: 7.1.5-1
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for pcp.

Unfortunately at time of writing/filling this bugreport there were
only the Red Hat bugzilla entries available (linked in the
security-tracker). Do you know moe, are those fixed in 7.2.0? (The CVE
ids are neither listed there).

CVE-2026-16524[0]:
| A command injection flaw in PCP's linux_sockets PMDA allows
| malicious shell metacharacters via the network.persocket.filter
| metric. This failed validation lets attackers execute arbitrary
| commands as the PMDA user when metrics refresh.


CVE-2026-16526[1]:
| A flaw in the PCP linux_sockets module exposes an unsecured internal
| connection. An attacker with initial code execution can exploit this
| to escalate privileges and execute arbitrary commands as root.


CVE-2026-16527[2]:
| An unauthenticated remote attacker can bypass access controls by
| sending crafted requests to the PCP pmproxy /store endpoint. This
| allows the attacker to overwrite any PMDA metric, leading to
| arbitrary code execution and system takeover.


CVE-2026-16529[3]:
| A signed integer overflow in the PCP __pmGetPDU() function can be
| exploited via crafted network packets during PDU processing or SASL
| negotiation. This permanently blinds the affected daemon, resulting
| in a total denial of service (DoS) for subsequent packet reads.


CVE-2026-16530[4]:
| A flaw was found in the PCP (Performance Co-Pilot) `pmproxy`
| service. A remote attacker can exploit a vulnerability in the
| `pmLogLoadInDom()` function by sending a specially crafted request.
| This bypasses a critical bounds check, which can lead to the
| `pmproxy` service crashing, causing a Denial of Service (DoS).
| Additionally, this flaw may enable the leakage of sensitive
| information from the system's memory.


CVE-2026-16531[5]:
| An unauthenticated remote attacker can exploit a path traversal
| vulnerability in the PCP pmproxy logger servlet using a crafted
| hostname. This allows arbitrary file and directory creation,
| potentially leading to a denial of service.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-16524
    https://www.cve.org/CVERecord?id=CVE-2026-16524
[1] https://security-tracker.debian.org/tracker/CVE-2026-16526
    https://www.cve.org/CVERecord?id=CVE-2026-16526
[2] https://security-tracker.debian.org/tracker/CVE-2026-16527
    https://www.cve.org/CVERecord?id=CVE-2026-16527
[3] https://security-tracker.debian.org/tracker/CVE-2026-16529
    https://www.cve.org/CVERecord?id=CVE-2026-16529
[4] https://security-tracker.debian.org/tracker/CVE-2026-16530
    https://www.cve.org/CVERecord?id=CVE-2026-16530
[5] https://security-tracker.debian.org/tracker/CVE-2026-16531
    https://www.cve.org/CVERecord?id=CVE-2026-16531

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Version: 7.2.1-2

Thanks Savatore, these issues are resolved by pcp-7.2.1 currently in
testing and unstable.

-- 
Nathan

--- End Message ---

Reply via email to