VDB

CVE-2026-16524

CVE-2026-16524 PUBLISHED CVSS 7.8 HIGH

Reported by redhat · Published July 30, 2026

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

Risk Scores

CVSS 3.1
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Red HatRed Hat Enterprise Linux 100:7.0.3-5.el10_2
Red HatRed Hat Enterprise Linux 80:5.3.7-22.el8_10.5
Red HatRed Hat Enterprise Linux 90:6.3.7-8.el9_8.4
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat Enterprise Linux 6
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat Enterprise Linux 7
Red HatRed Hat Enterprise Linux 100:7.0.3-5.el10_2
Red HatRed Hat Enterprise Linux 80:5.3.7-22.el8_10.5, 0:5.3.7-22.el8_10.5
Red HatRed Hat Enterprise Linux 90:6.3.7-8.el9_8.4

Timeline

  • Jul 30, 2026 EPSS Score
  • Jul 30, 2026 Coalition ESS Score
  • Jul 30, 2026 CVE Published
  • Aug 3, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 17, 2026 Distribution Patch
  • Aug 17, 2026 Security Advisory
  • Aug 18, 2026 Distribution Patch
  • Aug 18, 2026 Security Advisory
  • Aug 19, 2026 Distribution Patch
  • Aug 19, 2026 Security Advisory
  • Aug 20, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›