Fedora Account System
Red Hat Associate
Red Hat Customer
A command injection vulnerability exists in the linux_sockets PMDA through the writable metric network.persocket.filter. The validation helper sockets_check_filter() returns 1 for safe input and 0 for unsafe input, but the store handler uses an inverted condition: safe expressions are rejected while malicious ones containing shell metacharacters are silently accepted. The attacker-controlled filter value is later incorporated into a shell command executed via popen() whenever socket metrics are refreshed, enabling arbitrary command execution as the PMDA process user. Prerequisites: • linux_sockets PMDA loaded; • ss binary present (/usr/sbin/ss or /usr/bin/ss); • no [access] section restricting pmstore in pmcd.conf (default behavior).
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:55560 https://access.redhat.com/errata/RHSA-2026:55560
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:55740 https://access.redhat.com/errata/RHSA-2026:55740
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:55617 https://access.redhat.com/errata/RHSA-2026:55617