Back Linuxsecurity SUSE pcp Critical Command Injection and DoS Vulnerabilities Fix 2026-3507
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
## This update for pcp fixes the following issues: * CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922). * CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials (bsc#1272923). * CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924). * CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925). * CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926). * CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927). * Command injection in `pmieconf` `write_pmiefile` via `$ ` and `-f` (bsc#1272928). * Command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames
## This update for pcp fixes the following issues: * CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922). * CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials (bsc#1272923). * CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924). * CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925). * CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926). * CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927). * Command injection in `pmieconf` `write_pmiefile` via `$ ` and `-f` (bsc#1272928). * Command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames
* CVE-2026-16524 ( SUSE ): 9.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-16524 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16524 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16526 ( SUSE ): 8.5
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
* CVE-2026-16526 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16526 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
* CVE-2026-16527 ( SUSE ): 8.7
Announcement ID: SUSE-SU-2026:3507-1 Release Date: 2026-08-05T13:20:37Z Rating: critical
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
