Impact
A command injection flaw in PCP’s linux_sockets PMDA allows malicious shell meta characters to be supplied through the network.persocket.filter metric without proper validation. During a metrics refresh the flaw enables an attacker to inject and run arbitrary commands as the PMDA user, compromising the host with the same privileges the PMDA process holds. This results in a full system compromise, including credential theft and persistence mechanisms, classified as a high‑severity functional flaw (CWE‑78).
Affected Systems
The vulnerability impacts Red Hat Enterprise Linux releases 6, 7, 8, 9, 10 and Red Hat OpenShift Container Platform 4 through the PCP component. Systems that include the linux_sockets PMDA are vulnerable; the affected products are those listed in the CNA vendor/product names for the RHEL releases and OpenShift.
Risk and Exploitability
The CVSS score of 7.8 highlights high severity, while the EPSS score of 1% indicates exploitation is relatively uncommon but still possible. The CVE is not listed in CISA’s KEV catalog. The likely attack vector is remote, via the network.persocket.filter metric stream used during metric collection. An attacker who can inject malicious data into that stream can run arbitrary commands as the PMDA user, achieving full system compromise. Monitoring, restricting access, and disabling the PMDA when not required are critical to reducing risk.
OpenCVE Enrichment