Bug 2506026 (CVE-2026-16526) - CVE-2026-16526 PCP: PCP: Privilege escalation to root via linux_sockets PMDA vulnerability
Summary: CVE-2026-16526 PCP: PCP: Privilege escalation to root via linux_sockets PMDA ...
Keywords:
Status: NEW
Alias: CVE-2026-16526
Deadline: 2026-07-30
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2511464
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-22 07:26 UTC by OSIDB Bzimport
Modified: 2026-08-17 19:46 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:55560 0 None None None 2026-08-17 10:32:47 UTC
Red Hat Product Errata RHSA-2026:55617 0 None None None 2026-08-17 19:46:30 UTC
Red Hat Product Errata RHSA-2026:55740 0 None None None 2026-08-17 19:41:04 UTC

Description OSIDB Bzimport 2026-07-22 07:26:46 UTC
Summary: When the linux_sockets PMDA is loaded as a DSO inside PMCD, code execution
achieved via Vulnerability 3 (network.persocket.filter injection) can be escalated from user
pcp to root. The pmdarootfd Unix socket connection to pmdaroot is created without
O_CLOEXEC, causing all child processes spawned by popen() to inherit it. pmdaroot runs as
root and processes PDUROOT_STARTPMDA_REQ without per-request authentication,
executing attacker-controlled arguments via execvp() as root.
Prerequisites:
• Vulnerability 3 (linux_sockets command injection) required for initial code execution
- exploitable either locally via pmcd (TCP 44321, localhost only by default) or
remotely via the pmproxy REST API (TCP 44322, all interfaces by default, no
authentication required). linux_sockets
• PMDA loaded as DSO in PMCD (requires explicit configuration in pmcd.conf; default
is daemon mode).

Comment 1 errata-xmlrpc 2026-08-17 10:32:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:55560 https://access.redhat.com/errata/RHSA-2026:55560

Comment 2 errata-xmlrpc 2026-08-17 19:41:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55740 https://access.redhat.com/errata/RHSA-2026:55740

Comment 3 errata-xmlrpc 2026-08-17 19:46:29 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:55617 https://access.redhat.com/errata/RHSA-2026:55617


Note You need to log in before you can comment on or make changes to this bug.