CVE-2026-16526

Summary

A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-403: Exposure of File Descriptor to Unintended Control Sphere ('File Descriptor Leak')

Workarounds

To mitigate this vulnerability, ensure that the linux_sockets PMDA is not configured to load as a Dynamic Shared Object (DSO) within PMCD. The default configuration for this PMDA is daemon mode, which is not affected by this flaw. Review your pmcd.conf file to confirm the linux_sockets PMDA is not loaded as a DSO. If changes are made to pmcd.conf, a restart of the pmcd service is required for them to take effect.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References