VYPR

rpm package

opensuse/pcp&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/pcp&distro=openSUSE%20Tumbleweed

Vulnerabilities (10)

  • CVE-2026-16531MedJul 30, 2026
    affected < 6.3.8-3.1fixed 6.3.8-3.1

    An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.

  • CVE-2026-16530MedJul 30, 2026
    affected < 6.3.8-3.1fixed 6.3.8-3.1

    A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing,

  • CVE-2026-16529HigJul 30, 2026
    affected < 6.3.8-3.1fixed 6.3.8-3.1

    A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.

  • CVE-2026-16527HigJul 30, 2026
    affected < 6.3.8-3.1fixed 6.3.8-3.1

    An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.

  • CVE-2026-16526HigJul 30, 2026
    affected < 6.3.8-3.1fixed 6.3.8-3.1

    A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.

  • CVE-2026-16524HigJul 30, 2026
    affected < 6.3.8-3.1fixed 6.3.8-3.1

    A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

  • CVE-2024-45770MedSep 19, 2024
    affected < 6.3.8-1.1fixed 6.3.8-1.1

    A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which is used to log messages in the system. Under certain conditions, it runs with hig

  • CVE-2024-45769MedSep 19, 2024
    affected < 6.3.8-1.1fixed 6.3.8-1.1

    A vulnerability was found in Performance Co-Pilot (PCP).  This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash.

  • CVE-2019-3696HigMar 3, 2020
    affected < 5.2.2-3.4fixed 5.2.2-3.4

    A Improper Limitation of a Pathname to a Restricted Directory vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE

  • CVE-2019-3695HigMar 3, 2020
    affected < 5.2.2-3.4fixed 5.2.2-3.4

    A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Modu