Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. A command injection vulnerability exists in the linux_sockets PMDA through the writable metric network.persocket.filter. The validation helper sockets_check_filter() returns 1 for safe input and 0 for unsafe input, but the store handler uses an inverted condition: safe expressions are rejected while malicious ones containing shell metacharacters are silently accepted. The attacker-controlled filter value is later incorporated into a shell command executed via popen() whenever socket metrics are refreshed, enabling arbitrary command execution as the PMDA process user. Prerequisites: • linux_sockets PMDA loaded; • ss binary present (/usr/sbin/ss or /usr/bin/ss); • no [access] section restricting pmstore in pmcd.conf (default behavior).
This CVE has been addressed in the new pcp-7.2.0-1 RPM builds available for Fedora Rawhide, Fedora 44, and Fedora 43.