<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T11:05:33.121520+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:55560</id>
    <title>ALSA-2026:55560 — Important: pcp security update</title>
    <updated>2026-10-02T11:05:33.497534+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: pcp-conf, AlmaLinux:8: pcp-devel, AlmaLinux:8: pcp-doc, AlmaLinux:8: pcp-export-pcp2elasticsearch, AlmaLinux:8: pcp-export-pcp2graphite, AlmaLinux:8: pcp-export-pcp2influxdb, AlmaLinux:8: pcp-export-pcp2json, AlmaLinux:8: pcp-export-pcp2spark, AlmaLinux:8: pcp-export-pcp2xml, AlmaLinux:8: pcp-export-pcp2zabbix and 68 more</p>
<p>Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems.</p>
<p>Security Fix(es):</p>
<p>* PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection (CVE-2026-16524)
  * PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability (CVE-2026-16526)
  * PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules (CVE-2026-16527)
  * PCP: PCP: Denial of Service due to signed integer overflow (CVE-2026-16529)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:55560"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-381986</id>
    <title>EUVD-2026-381986</title>
    <updated>2026-10-02T11:05:33.497772+00:00</updated>
    <content>EUVD-2026-381986</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-381986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-16527</id>
    <title>fkie_cve-2026-16527</title>
    <updated>2026-10-02T11:05:33.497802+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-16527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cf63-g57m-mc5r</id>
    <title>GHSA-cf63-g57m-mc5r</title>
    <updated>2026-10-02T11:05:33.497840+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cf63-g57m-mc5r"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3807</id>
    <title>OESA-2026-3807 — pcp security update</title>
    <updated>2026-10-02T11:05:33.497867+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP4: pcp</p>
<p>Performance Co-Pilot (PCP) provides a framework and services to support system-level performance monitoring and performance management.

Security Fix(es):</p>
<p>A command injection flaw in PCP&amp;apos;s linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.(CVE-2026-16524)</p>
<p>A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.(CVE-2026-16526)</p>
<p>An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.(CVE-2026-16527)</p>
<p>A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.(CVE-2026-16529)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3807"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11490-1</id>
    <title>openSUSE-SU-2026:11490-1 — libpcp-devel-6.3.8-3.1 on GA media</title>
    <updated>2026-10-02T11:05:33.497917+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libpcp-devel-6.3.8-3.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11490-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:72272</id>
    <title>RHSA-2026:72272 — Red Hat Security Advisory: pcp security update</title>
    <updated>2026-10-02T11:05:33.497951+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules PCP: PCP: Denial of Service due to signed integer overflow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:72272"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:55560</id>
    <title>RLSA-2026:55560 — Important: pcp security update</title>
    <updated>2026-10-02T11:05:33.497988+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: pcp</p>
<p>Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems.</p>
<p>Security Fix(es):</p>
<p>* PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection (CVE-2026-16524)</p>
<p>* PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability (CVE-2026-16526)</p>
<p>* PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules (CVE-2026-16527)</p>
<p>* PCP: PCP: Denial of Service due to signed integer overflow (CVE-2026-16529)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:55560"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23064-1</id>
    <title>SUSE-SU-2026:23064-1 — Security update for pcp</title>
    <updated>2026-10-02T11:05:33.498036+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for pcp</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23064-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16527</id>
    <title>UBUNTU-CVE-2026-16527</title>
    <updated>2026-10-02T11:05:33.498067+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: pcp, Ubuntu:18.04:LTS: pcp, Ubuntu:20.04:LTS: pcp, Ubuntu:22.04:LTS: pcp, Ubuntu:24.04:LTS: pcp, Ubuntu:26.04:LTS: pcp</p>
<p>An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16527"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2868</id>
    <title>WID-SEC-W-2026-2868 — Red Hat Enterprise Linux (pcp): Mehrere Schwachstellen</title>
    <updated>2026-10-02T11:05:33.498110+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (pcp) ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2868"/>
  </entry>
</feed>
