RHSA-2026:55560: Important: pcp security update
Important: pcp security update
Other sources
Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems.Security Fix(es): PCP: PCP linuxsockets PMDA: Arbitrary Command Execution via Command Injection (CVE-2026-16524) PCP: PCP: Privilege escalation to root via linuxsockets PMDA vulnerability (CVE-2026-16526) PCP: PCP pmproxy: Unauthenticated access to /store endpoint allows bypassing pmcd access rules (CVE-2026-16527) PCP: PCP: Denial of Service due to signed integer overflow (CVE-2026-16529) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/pcp-confto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-debugsourceto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-develto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-docto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-export-pcp2elasticsearchto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-export-pcp2graphiteto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-export-pcp2influxdbto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-export-pcp2sparkto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-export-pcp2zabbixto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-export-zabbix-agentto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-gui-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-import-collectl2pcp-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-import-ganglia2pcpto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-apache-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-bondingto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-bpftraceto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-dbpingto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-denkito a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-denki-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-dmto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-dm-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-dockerto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-ds389to a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-gfs2to a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-gfs2-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-glusterto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-haproxyto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-infinibandto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-jsonto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-lmsensorsto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-lustrecommto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-lustrecomm-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-mailqto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-mailq-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-memcacheto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-mssqlto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-mysqlto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-namedto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-netcheckto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-newsto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-nfsclientto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-perfevent-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-roomtempto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-sendmailto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-shpingto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-shping-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-statsdto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-statsd-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-summaryto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-summary-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-systemd-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-unboundto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-weblog-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-selinuxto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-testsuiteto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-zeroconfto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-export-pcp2xmlto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-import-sar2pcpto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-activemqto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-bashto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-bccto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-cisco-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-ds389logto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-gpfsto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-haclusterto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-hacluster-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-micto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-mounts-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-openmetricsto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-podmanto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-rabbitmqto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-sambato a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-slurmto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-socketsto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-systemdto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-system-toolsto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-export-zabbix-agent-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-guito a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-import-collectl2pcpto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-import-iostat2pcpto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-apacheto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-bash-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-elasticsearchto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-netfilterto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-postfixto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-trace-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-pmda-weblogto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5 - Upgrade
Upgrade
redhat/pcp-confto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-develto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-export-pcp2jsonto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-export-pcp2xmlto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-export-pcp2zabbixto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-export-zabbix-agentto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-gui-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-import-ganglia2pcpto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-import-iostat2pcpto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-libsto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-apacheto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-ciscoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-denki-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-dm-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-dockerto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-gfs2to a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-glusterto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-gpfsto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-haclusterto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-jsonto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-libvirtto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-lioto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-lustreto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-mailq-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-mounts-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-mysqlto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-namedto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-netcheckto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-openvswitchto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-perfevent-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-podman-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-postfixto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-postgresqlto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-roomtempto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-shping-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-statsdto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-summaryto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-summary-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-systemdto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-systemd-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-traceto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-pmda-unboundto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-selinuxto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-system-toolsto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-system-tools-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa - Upgrade
Upgrade
redhat/pcp-testsuiteto a version that resolves this vulnerability.Fixed in 5.3.7-22.el8_10.5.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:55560?
The severity of RHSA-2026:55560 is classified as high, with a score of 7.
How do I fix RHSA-2026:55560?
To fix RHSA-2026:55560, update the affected PCP packages to their latest versions provided by Red Hat.
What vulnerabilities are associated with RHSA-2026:55560?
RHSA-2026:55560 is associated with vulnerabilities including Integer Overflow and Command Injection.
What software is affected by RHSA-2026:55560?
Affected software by RHSA-2026:55560 includes redhat/pcp-devel, redhat/pcp-export-zabbix-agent, and several redhat/pcp-pmda packages.
When was RHSA-2026:55560 published?
RHSA-2026:55560 was published on August 17, 2026.