CVE-2024-45769: Pcp: pmcd heap corruption through metric pmstore operations
A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash.
Other sources
The PCP libpcp pmDecodeValueSet routine mishandles size checks in the Result PDU, allowing the pmcd metric store operation (if enabled) to corrupt the calling program's heap with a maliciously crafted PDU.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45769?
CVE-2024-45769 has a high severity rating due to its potential to cause program crashes or misbehavior.
How do I fix CVE-2024-45769?
To fix CVE-2024-45769, update Performance Co-Pilot to the latest patched version provided by the vendor.
What systems are affected by CVE-2024-45769?
CVE-2024-45769 affects Performance Co-Pilot software environments where the vulnerability exists.
What impact does CVE-2024-45769 have on system performance?
CVE-2024-45769 can lead to performance degradation by causing the Performance Co-Pilot program to crash or misbehave.
Is CVE-2024-45769 easy to exploit?
Yes, CVE-2024-45769 can be exploited by sending specially crafted data, making it relatively straightforward for attackers.