CVE-2024-45769: Pcp: pmcd heap corruption through metric pmstore operations

Published Sep 6, 2024
·
Updated

A vulnerability was found in Performance Co-Pilot (PCP).  This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash.

Other sources

The PCP libpcp pmDecodeValueSet routine mishandles size checks in the Result PDU, allowing the pmcd metric store operation (if enabled) to corrupt the calling program's heap with a maliciously crafted PDU.

Red Hat

Affected Software

1 affected component
Performance Co-Pilot Performance Co-Pilot

Event History

Sep 6, 2024
Data Sourced
via Red Hat·05:17 PM
DescriptionSeverityAffected Software
Sep 19, 2024
CVE Published
via MITRE·08:45 AM
Data Sourced
via MITRE·08:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2024-45769?

CVE-2024-45769 has a high severity rating due to its potential to cause program crashes or misbehavior.

2

How do I fix CVE-2024-45769?

To fix CVE-2024-45769, update Performance Co-Pilot to the latest patched version provided by the vendor.

3

What systems are affected by CVE-2024-45769?

CVE-2024-45769 affects Performance Co-Pilot software environments where the vulnerability exists.

4

What impact does CVE-2024-45769 have on system performance?

CVE-2024-45769 can lead to performance degradation by causing the Performance Co-Pilot program to crash or misbehave.

5

Is CVE-2024-45769 easy to exploit?

Yes, CVE-2024-45769 can be exploited by sending specially crafted data, making it relatively straightforward for attackers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203