Issued at: 2024-09-30
Updated at: 2024-09-30
Synopsis
Important: pcp security update
Description
Performance Co-Pilot (PCP) is a suite of tools, services, and libraries for acquisition, archiving, and analysis of system-level performance measurements. Its light-weight distributed architecture makes it particularly well-suited to centralized analysis of complex systems.
Security Fix(es):
* pcp: pmpost symlink attack allows escalating pcp to root user (CVE-2024-45770)
* pcp: pmcd heap corruption through metric pmstore operations (CVE-2024-45769)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.