<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:15:02 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:55560 — Important: pcp security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:55560</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: pcp-conf, AlmaLinux:8: pcp-devel, AlmaLinux:8: pcp-doc, AlmaLinux:8: pcp-export-pcp2elasticsearch, AlmaLinux:8: pcp-export-pcp2graphite, AlmaLinux:8: pcp-export-pcp2influxdb, AlmaLinux:8: pcp-export-pcp2json, AlmaLinux:8: pcp-export-pcp2spark, AlmaLinux:8: pcp-export-pcp2xml, AlmaLinux:8: pcp-export-pcp2zabbix and 68 more&lt;/p&gt;
&lt;p&gt;Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection (CVE-2026-16524)
  * PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability (CVE-2026-16526)
  * PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules (CVE-2026-16527)
  * PCP: PCP: Denial of Service due to signed integer overflow (CVE-2026-16529)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: pcp-conf, AlmaLinux:8: pcp-devel, AlmaLinux:8: pcp-doc, AlmaLinux:8: pcp-export-pcp2elasticsearch, AlmaLinux:8: pcp-export-pcp2graphite, AlmaLinux:8: pcp-export-pcp2influxdb, AlmaLinux:8: pcp-export-pcp2json, AlmaLinux:8: pcp-export-pcp2spark, AlmaLinux:8: pcp-export-pcp2xml, AlmaLinux:8: pcp-export-pcp2zabbix and 68 more&lt;/p&gt;
&lt;p&gt;Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection (CVE-2026-16524)
  * PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability (CVE-2026-16526)
  * PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules (CVE-2026-16527)
  * PCP: PCP: Denial of Service due to signed integer overflow (CVE-2026-16529)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:55560</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1256 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256</link>
      <description>certfr-2026-avi-1256</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1256</guid>
    </item>
    <item>
      <title>EUVD-2026-381987</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-381987</link>
      <description>EUVD-2026-381987</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-381987</guid>
    </item>
    <item>
      <title>fkie_cve-2026-16529</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-16529</link>
      <description>&lt;p&gt;A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-16529</guid>
    </item>
    <item>
      <title>GHSA-hm96-wjh8-qqgm</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-hm96-wjh8-qqgm</link>
      <description>&lt;p&gt;A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-hm96-wjh8-qqgm</guid>
    </item>
    <item>
      <title>OESA-2026-3807 — pcp security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3807</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: pcp&lt;/p&gt;
&lt;p&gt;Performance Co-Pilot (PCP) provides a framework and services to support system-level performance monitoring and performance management.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A command injection flaw in PCP&amp;amp;apos;s linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.(CVE-2026-16524)&lt;/p&gt;
&lt;p&gt;A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.(CVE-2026-16526)&lt;/p&gt;
&lt;p&gt;An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.(CVE-2026-16527)&lt;/p&gt;
&lt;p&gt;A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.(CVE-2026-16529)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: pcp&lt;/p&gt;
&lt;p&gt;Performance Co-Pilot (PCP) provides a framework and services to support system-level performance monitoring and performance management.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A command injection flaw in PCP&amp;amp;apos;s linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.(CVE-2026-16524)&lt;/p&gt;
&lt;p&gt;A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.(CVE-2026-16526)&lt;/p&gt;
&lt;p&gt;An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.(CVE-2026-16527)&lt;/p&gt;
&lt;p&gt;A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.(CVE-2026-16529)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3807</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11490-1 — libpcp-devel-6.3.8-3.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11490-1</link>
      <description>&lt;p&gt;libpcp-devel-6.3.8-3.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libpcp-devel-6.3.8-3.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11490-1</guid>
    </item>
    <item>
      <title>RHSA-2026:72272 — Red Hat Security Advisory: pcp security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:72272</link>
      <description>&lt;p&gt;PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules PCP: PCP: Denial of Service due to signed integer overflow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules PCP: PCP: Denial of Service due to signed integer overflow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:72272</guid>
    </item>
    <item>
      <title>RLSA-2026:55560 — Important: pcp security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:55560</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: pcp&lt;/p&gt;
&lt;p&gt;Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection (CVE-2026-16524)&lt;/p&gt;
&lt;p&gt;* PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability (CVE-2026-16526)&lt;/p&gt;
&lt;p&gt;* PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules (CVE-2026-16527)&lt;/p&gt;
&lt;p&gt;* PCP: PCP: Denial of Service due to signed integer overflow (CVE-2026-16529)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: pcp&lt;/p&gt;
&lt;p&gt;Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* PCP: PCP linux_sockets PMDA: Arbitrary Command Execution via Command Injection (CVE-2026-16524)&lt;/p&gt;
&lt;p&gt;* PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability (CVE-2026-16526)&lt;/p&gt;
&lt;p&gt;* PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules (CVE-2026-16527)&lt;/p&gt;
&lt;p&gt;* PCP: PCP: Denial of Service due to signed integer overflow (CVE-2026-16529)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:55560</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23064-1 — Security update for pcp</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23064-1</link>
      <description>&lt;p&gt;Security update for pcp&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for pcp&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23064-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-16529</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16529</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: pcp, Ubuntu:18.04:LTS: pcp, Ubuntu:20.04:LTS: pcp, Ubuntu:22.04:LTS: pcp, Ubuntu:24.04:LTS: pcp, Ubuntu:26.04:LTS: pcp&lt;/p&gt;
&lt;p&gt;A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: pcp, Ubuntu:18.04:LTS: pcp, Ubuntu:20.04:LTS: pcp, Ubuntu:22.04:LTS: pcp, Ubuntu:24.04:LTS: pcp, Ubuntu:26.04:LTS: pcp&lt;/p&gt;
&lt;p&gt;A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-16529</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2868 — Red Hat Enterprise Linux (pcp): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2868</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (pcp) ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (pcp) ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2868</guid>
    </item>
  </channel>
</rss>
