[Git][security-tracker-team/security-tracker][master] Update status on pcp issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 25 07:13:18 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1b1b184e by Salvatore Bonaccorso at 2026-08-25T08:11:57+02:00
Update status on pcp issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -30012,17 +30012,21 @@ CVE-2026-16610 (The Admin and Site Enhancements (ASE) Pro plugin for WordPress i
 CVE-2026-16553 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-16531 (An unauthenticated remote attacker can exploit a path traversal vulner ...)
-	- pcp 7.2.1-2 (bug #1143154)
+	- pcp 7.2.0-1 (bug #1143154)
 	[trixie] - pcp <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506037
+	NOTE: Fixed by: https://github.com/performancecopilot/pcp/commit/dd6ed05f143f97e00198cb4b0180c6375d758cbe (7.2.0)
 CVE-2026-16530 (A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service.  ...)
 	- pcp 7.2.1-2 (bug #1143154)
 	[trixie] - pcp <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506033
+	NOTE: Fixed by: https://github.com/performancecopilot/pcp/commit/ec81e2b35c7dc19a69406d2712d1b9904ac22112 (7.2.0)
+	NOTE: Followup: https://github.com/performancecopilot/pcp/commit/60e20c972306f195e8ba13bc9927e4e7798940b2 (7.2.1)
 CVE-2026-16529 (A signed integer overflow in the PCP __pmGetPDU() function can be expl ...)
-	- pcp 7.2.1-2 (bug #1143154)
+	- pcp 7.2.0-1 (bug #1143154)
 	[trixie] - pcp <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506032
+	NOTE: Fixed by: https://github.com/performancecopilot/pcp/commit/a9fa73d3ba2d24f9a6a0374b82936e7145cd2794 (7.2.0)
 CVE-2026-16527 (An unauthenticated remote attacker can bypass access controls by sendi ...)
 	- pcp 7.2.1-2 (bug #1143154)
 	[trixie] - pcp <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1b1b184eecdde809aee9e155d3dbae563cbedea4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1b1b184eecdde809aee9e155d3dbae563cbedea4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/1122e956/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list