An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
No analysis available yet.
Vendor Workaround
To mitigate this vulnerability, ensure that the `linux_sockets` PMDA is not configured to load as a Dynamic Shared Object (DSO) within PMCD. The default configuration for this PMDA is daemon mode, which is not affected by this flaw. Review your `pmcd.conf` file to confirm the `linux_sockets` PMDA is not loaded as a DSO. If changes are made to `pmcd.conf`, a restart of the `pmcd` service is required for them to take effect.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 05:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root. | |
| Title | Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| Weaknesses | CWE-403 | |
| CPEs | cpe:/a:redhat:openshift:4 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat openshift |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-07-30T05:20:07.504Z
Reserved: 2026-07-22T07:26:46.736Z
Link: CVE-2026-16526
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-403
Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')