Red Hat Security Advisory: pcp security update
🔗 CVE IDs covered (4)
📋 Description
CVE-2026-16524 — PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection CVE-2026-16526 — PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability CVE-2026-16527 — PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules CVE-2026-16529 — PCP: PCP: Denial of Service due to signed integer overflow
🎯 Affected products200
- Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-0:6.2.0-5.el9_4.2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-0:6.2.0-5.el9_4.2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-0:6.2.0-5.el9_4.2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-0:6.2.0-5.el9_4.2.src as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-0:6.2.0-5.el9_4.2.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-conf-0:6.2.0-5.el9_4.2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-conf-0:6.2.0-5.el9_4.2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-conf-0:6.2.0-5.el9_4.2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-conf-0:6.2.0-5.el9_4.2.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-debuginfo-0:6.2.0-5.el9_4.2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-debuginfo-0:6.2.0-5.el9_4.2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-debuginfo-0:6.2.0-5.el9_4.2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-debuginfo-0:6.2.0-5.el9_4.2.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-debugsource-0:6.2.0-5.el9_4.2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-debugsource-0:6.2.0-5.el9_4.2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-debugsource-0:6.2.0-5.el9_4.2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-debugsource-0:6.2.0-5.el9_4.2.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-devel-0:6.2.0-5.el9_4.2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-devel-0:6.2.0-5.el9_4.2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-devel-0:6.2.0-5.el9_4.2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-devel-0:6.2.0-5.el9_4.2.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-devel-debuginfo-0:6.2.0-5.el9_4.2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-devel-debuginfo-0:6.2.0-5.el9_4.2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-devel-debuginfo-0:6.2.0-5.el9_4.2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-devel-debuginfo-0:6.2.0-5.el9_4.2.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-doc-0:6.2.0-5.el9_4.2.noarch as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-export-pcp2elasticsearch-0:6.2.0-5.el9_4.2.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-export-pcp2elasticsearch-0:6.2.0-5.el9_4.2.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- pcp-export-pcp2elasticsearch-0:6.2.0-5.el9_4.2.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.9.4)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To prevent exploitation, restrict access to the `pmstore` utility by configuring the `[access]` section in `/etc/pcp/pmcd/pmcd.conf`. If the `linux_sockets` PMDA is not essential, it can be unloaded or disabled to remove the attack vector. After modifying `pmcd.conf`, the `pmcd` service must be restarted for changes to take effect. Workaround: To mitigate this vulnerability, ensure that the `linux_sockets` PMDA is not configured to load as a Dynamic Shared Object (DSO) within PMCD. The default configuration for this PMDA is daemon mode, which is not affected by this flaw. Review your `pmcd.conf` file to confirm the `linux_sockets` PMDA is not loaded as a DSO. If changes are made to `pmcd.conf`, a restart of the `pmcd` service is required for them to take effect. Workaround: To mitigate this issue, restrict network access to the pmproxy service (port 44322/TCP) to trusted hosts only using firewall rules. If pmproxy functionality is not required, disable the service. Disabling the service will prevent remote access to performance metrics via pmproxy. To disable the service, run: `sudo systemctl stop pmproxy` and `sudo systemctl disable pmproxy`. If firewalling, ensure to reload the firewall rules after making changes. Workaround: To mitigate this issue, ensure that Performance Co-Pilot (PCP) services, specifically `pmlogger` and `pmcd`, are not exposed to untrusted networks. By default, these services are configured to listen only on the loopback interface, which prevents remote exploitation. If these default network bindings have been altered, revert them to restrict access to localhost. For `pmlogger`, ensure the `PMLOGGER_LOCAL` environment variable is set. If remote access to PCP services is not required, consider implementing firewall rules to block external connections to TCP ports 4330 (pmlogger) and 44321 (pmcd). Changes to network configurations or environment variables may require restarting the affected PCP services for the mitigation to take effect.
🔗 References (7)
- selfhttps://access.redhat.com/errata/RHSA-2026:72593
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2506023
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2506026
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2506031
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2506032
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_72593.json