Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:55560: Important: pcp security update

This Red Hat security advisory addresses four Important-severity vulnerabilities in Performance Co-Pilot (PCP) for RHEL 8, including command injection and privilege escalation via the linux_sockets PMDA (CVE-2026-16524, CVSS 7.8; CVE-2026-16526, CVSS 8.8), unauthenticated access bypass via pmproxy (CVE-2026-16527, CVSS 7.3), and a denial of service via integer overflow (CVE-2026-16529). The vulnerabilities are resolved in the updated package version pcp-5.3.7-22.el8_10.5 for all supported RHEL 8 architectures. Administrators should apply this update promptly to mitigate the risks of arbitrary command execution and privilege escalation to root.
Read Full Article →

Red Hat Product Errata RHSA-2026:55560 - Security Advisory Issued: 2026-08-17 Updated: 2026-08-17 RHSA-2026:55560 - Security Advisory Overview Updated Packages Synopsis Important: pcp security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for pcp is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems. Security Fix(es): PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection (CVE-2026-16524) PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability (CVE-2026-16526) PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules (CVE-2026-16527) PCP: PCP: Denial of Service due to signed integer overflow (CVE-2026-16529) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2506023 - CVE-2026-16524 PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection BZ - 2506026 - CVE-2026-16526 PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability BZ - 2506031 - CVE-2026-16527 PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules BZ - 2506032 - CVE-2026-16529 PCP: PCP: Denial of Service due to signed integer overflow CVEs CVE-2026-16524 CVE-2026-16526 CVE-2026-16527 CVE-2026-16529 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM pcp-5.3.7-22.el8_10.5.src.rpm SHA-256: 97fa7ad9bd9bdb0097436f8eab54bc1c1b7736bf016013093889e4451422fb9f x86_64 pcp-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: dbbe2a92e6f250cc7d630de624d6d04656afe1fe3eb21d7b20628b4c3c137817 pcp-conf-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: bd1d0c26a7b9333c5c05f40044ef6dc2b2e116c656932f9b228fbe6f2979ebe8 pcp-debuginfo-5.3.7-22.el8_10.5.i686.rpm SHA-256: a6c41fcd64f83daaa9f4ed0208c73a71488d32f4d531f9e21b6583f4291aecfd pcp-debuginfo-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: db5ee34cc88f60297d9f0df30fe023f2a511004ee84cafd330afa35c75cbb397 pcp-debugsource-5.3.7-22.el8_10.5.i686.rpm SHA-256: beabc37e5b12bacc03a52446e81538dbb0a36a37ea61bcd2e8583e37f589b66a pcp-debugsource-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: b4172986cd1e07bbb2b2915dd567d00d7a4f0ca2fb7fa39d052e56c1b30848e9 pcp-devel-5.3.7-22.el8_10.5.i686.rpm SHA-256: baaf5a28cb43dc59c30742736579d35c1d2075e5b22fa1067bcd585f09c2670d pcp-devel-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: a9b4db521de9a7d347f3bdbfab7775d91181733745ad23481f06b7088e90d551 pcp-devel-debuginfo-5.3.7-22.el8_10.5.i686.rpm SHA-256: 4511f22f72bbc0fd5eef71f4702ebb5cc3623a705eaada0a7eaaf6adf58044be pcp-devel-debuginfo-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: adef32eb7b9eb199c9bf3ac4901da29950bf6991e12ff76431ad934fd6e8a1fb pcp-doc-5.3.7-22.el8_10.5.noarch.rpm SHA-256: ef00d797c054e0fbd0cf2596210ee2306245382aad708a52832e15d524ee5f6e pcp-export-pcp2elasticsearch-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 537bb0dbf3b50e5c82671c128e90fa5637123bf733a04df395399fd9cb6d9d4e pcp-export-pcp2graphite-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: aa7e86490d9cc72858457051b380deb3c11d0af1e1bd496b1c0c682df2887b44 pcp-export-pcp2influxdb-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: cbf91a4c093cc53709cb17a99d6add04c88a1d496b1e46be97927266de43b16a pcp-export-pcp2json-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: c9d108118fdbff24f31813daf37ade1c9a0d7def2bf233abb7e51fd285d6eaf3 pcp-export-pcp2spark-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: a0f5915eafabbab35a4d8c29fff3b45651c65abc0fcc3ad57c315ea7b6b86c69 pcp-export-pcp2xml-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: cef94b63969eda07a2542357fb27b1497442acb333b33dc4e21ee3c65f809058 pcp-export-pcp2zabbix-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: f09b9630a0278e8a090d4a432db188268fc72d7988271e547fef9e1104af9f57 pcp-export-zabbix-agent-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: d8740aaaf8c976a3f563d18bfea2c1df2d32b9d8c9e2b0ece6e9f531daf4cdd5 pcp-export-zabbix-agent-debuginfo-5.3.7-22.el8_10.5.i686.rpm SHA-256: 2b8c4c4063c5382258a0c499213934df2e5b997cda36efcace34b52edd8c06d0 pcp-export-zabbix-agent-debuginfo-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: feea116eef81250a65d2daf27eda85be2493c44346974b000d1db83a14f889d3 pcp-gui-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 2baaa73ce467172cc30f0a2542429dfca9b874bd7dd0b278253d458a2b0e6a74 pcp-gui-debuginfo-5.3.7-22.el8_10.5.i686.rpm SHA-256: 27bc04a4d7e5919a4bcca327156f20696404b555791499db0f9b75f1f70885d3 pcp-gui-debuginfo-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 3035852fd6fbcbe0d11654aae4a757c6637632397fa5e1ec6330f683483ede76 pcp-import-collectl2pcp-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 963418b8189520a76aca8ca3218efc820362b6fd6ac54b7d62f14ce6c4fb47a2 pcp-import-collectl2pcp-debuginfo-5.3.7-22.el8_10.5.i686.rpm SHA-256: ca24e4a65308a141405eec0e9d5d451db949584f84f25dd7fc9ab3fb5f249c6a pcp-import-collectl2pcp-debuginfo-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 95e6f27097b8ee7dcfa0832935534cc87222ca4e4f66eb210a8a22044a7f9b70 pcp-import-ganglia2pcp-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 26df2422499d76a0e7d3e44958aa76705ef8f63eb82bad6f9e58a842e7961025 pcp-import-iostat2pcp-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 71d3fa3030c55590cd9088e6e9c0c17e0f5d36bad6fe8ec4f25fc3590c811672 pcp-import-mrtg2pcp-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 93dcfbddca954a9c925dbf597944dd8625a0c3a479732cf9f1f6173fbb5a29c1 pcp-import-sar2pcp-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 4c18e8a213c286ac43fb669e06cdd2d4b20f572ddda1ca2e4b7ed56eb7e4302f pcp-libs-5.3.7-22.el8_10.5.i686.rpm SHA-256: 3dfc140dd986247ed05eee593e7532a24796536b312b82783f928a372bcdcfbb pcp-libs-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: e6d9d26940d392e4df57e8e7359f947ff1370a20ac3d0230e32ac744c3dd8241 pcp-libs-debuginfo-5.3.7-22.el8_10.5.i686.rpm SHA-256: 2edf8b520dff8a6f8772092e5aad45b9e16890eb6370b876b81e2bcc237a8b9c pcp-libs-debuginfo-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 228ad6bfe551f60b4b16b0c1dffacddd3fb058240264cdb3c343afa3746bf38d pcp-libs-devel-5.3.7-22.el8_10.5.i686.rpm SHA-256: a7afaed220ed2a624be895af97cc338a6ca56ebb53bcf92657bc6fc570fab411 pcp-libs-devel-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: f9f5cafabbfb1202226d9f6fd9efb84faedd7a2f17c800196d6e135ee1db3205 pcp-pmda-activemq-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: a10b0b2c318711245bca9e0eb782f139f11f488645002b7ef468f6d9c1f7539b pcp-pmda-apache-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: cc7f499e9b8a9d021eec65fad6a87644c8f33954005662688d419c3571242a6d pcp-pmda-apache-debuginfo-5.3.7-22.el8_10.5.i686.rpm SHA-256: cf920fddfbad42935cd908e64c5e36de5285cbda0d5c9f08a456d87cdca08917 pcp-pmda-apache-debuginfo-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 1b679e4b825397ed11c1957687d414a5042e257c6020771a098507ca383ff249 pcp-pmda-bash-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 6b621c070cb643b44373dc9608106f3050e4e3a46246833d395d6ef53ab9df89 pcp-pmda-bash-debuginfo-5.3.7-22.el8_10.5.i686.rpm SHA-256: 350db77d5e4ed479276d9b0a66200285da7b747f5315a130ced7449cd24f71d9 pcp-pmda-bash-debuginfo-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 747c9d8a845c623225015c964d189631e88272fdbf16f4af5ccba747c27fd6c8 pcp-pmda-bcc-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 4da707a88d5021236034017030cbdd61c24630087853b20b62b5e0405c06ba24 pcp-pmda-bind2-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 3e695d3d6a7c6ba887cd8df97d1bf60c3c3df98088bc99e480d020ad4cf30054 pcp-pmda-bonding-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 4384825519c5da9662dcb3b7137291e93af2d5757a022937bdccceee680339df pcp-pmda-bpftrace-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 95cd2293c5655cf29e7c779ae3e4a9bca04ea43bdc32fb1710651b558fee1289 pcp-pmda-cifs-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 059e05be17ad65b4b166d63d5ff9742f530e7fac3297479b45cd46f59a074cdc pcp-pmda-cifs-debuginfo-5.3.7-22.el8_10.5.i686.rpm SHA-256: 1e94dd422b6dcd8d3ae16366dc195d360347d0c5b0ef32c279d46373f800a681 pcp-pmda-cifs-debuginfo-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 0a86ceacac74f8be6ef258e4419a03996123b9acc6522bcfe762bf25d5a19875 pcp-pmda-cisco-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 3fddaaaf964677849fd34e0383cfa0d9f2b775a6de0918bcc39dcf865ee26297 pcp-pmda-cisco-debuginfo-5.3.7-22.el8_10.5.i686.rpm SHA-256: b10855dd96c1c279f7b9de8313c8a62d3deb7e210aee03efa556ab78cc538cfe pcp-pmda-cisco-debuginfo-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: f0d78ab5facb262f4988af0c1bc8ca9b7be30e8ef4cd66a52f2d3a1404570f6f pcp-pmda-dbping-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 79b5b6a88585bdf6e8d064d37c3bea94e96bb80f1b5e612cd08cf4ce2b864151 pcp-pmda-denki-5.3.7-22.el8_10.5.x86_64.rpm SHA-256: 75793fd667a84f8a72cd3b39c5781d77c19af67d805d3bebba76a7783230f50d pcp-pmda-denki-debuginfo-5.3.7-22.el8_10.5.i686.rpm SHA-256: 959eb5c874df2561769da79545e2a0c2d635c8f468bba85

Share this article