This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
To prevent exploitation, restrict access to the `pmstore` utility by configuring the `[access]` section in `/etc/pcp/pmcd/pmcd.conf`. If the `linux_sockets` PMDA is not essential, it can be unloaded or disabled to remove the attack vector. After modifying `pmcd.conf`, the `pmcd` service must be restarted for changes to take effect.
Thu, 30 Jul 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh. | |
| Title | Pcp: pcp linux_sockets pmda: arbitrary command execution via command injection | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-07-30T05:15:15.277Z
Reserved: 2026-07-22T06:52:16.739Z
Link: CVE-2026-16524
No data.
No data.
No data.
OpenCVE Enrichment
No data.