This update for pcp fixes the following issues:
Upgrade to 6.2.0 (bsc#1217826 / PED#8192):
* CVE-2024-45770: Fixed symlink race (bsc#1230552).
* CVE-2024-45769: Fixed pmstore corruption (bsc#1230551)
* CVE-2023-6917: Fixed local privilege escalation from pcp user to root
(bsc#1217826).
Bug fixes:
* Reintroduce libuv support for SLE >= 15 (bsc#1231345).
* move pmlogger_daily into main package (bsc#1222815)
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* openSUSE Leap 15.4
zypper in -t patch SUSE-2025-11=1
* openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586)
* pcp-pmda-summary-6.2.0-150400.5.9.1
* pcp-pmda-summary-debuginfo-6.2.0-150400.5.9.1
* libpcp_mmv1-6.2.0-150400.5.9.1
* libpcp3-debuginfo-6.2.0-150400.5.9.1
* libpcp_web1-debuginfo-6.2.0-150400.5.9.1
* pcp-devel-6.2.0-150400.5.9.1
* pcp-pmda-cifs-debuginfo-6.2.0-150400.5.9.1
* pcp-pmda-sockets-debuginfo-6.2.0-150400.5.9.1
* libpcp_trace2-6.2.0-150400.5.9.1
* pcp-devel-debuginfo-6.2.0-150400.5.9.1
* pcp-import-collectl2pcp-6.2.0-150400.5.9.1
* pcp-pmda-bind2-6.2.0-150400.5.9.1
* pcp-pmda-smart-6.2.0-150400.5.9.1
* pcp-testsuite-debuginfo-6.2.0-150400.5.9.1
* libpcp_web1-6.2.0-150400.5.9.1
* pcp-pmda-docker-6.2.0-150400.5.9.1
* pcp-pmda-cifs-6.2.0-150400.5.9.1
* pcp-testsuite-6.2.0-150400.5.9.1
* pcp-pmda-nvidia-gpu-debuginfo-6.2.0-150400.5.9.1
* pcp-pmda-zimbra-debuginfo-6.2.0-150400.5.9.1
* pcp-system-tools-6.2.0-150400.5.9.1
* pcp-pmda-shping-6.2.0-150400.5.9.1
* pcp-6.2.0-150400.5.9.1
* libpcp-devel-6.2.0-150400.5.9.1
*...
Read the Full Advisory* bsc#1217826
* bsc#1222815
* bsc#1230551
* bsc#1230552
* bsc#1231345
## References:
* https://www.suse.com/security/cve/CVE-2023-6917.html
* https://www.suse.com/security/cve/CVE-2024-45769.html
* https://www.suse.com/security/cve/CVE-2024-45770.html
* https://bugzilla.suse.com/show_bug.cgi?id=1217826
* https://bugzilla.suse.com/show_bug.cgi?id=1222815
* https://bugzilla.suse.com/show_bug.cgi?id=1230551
* https://bugzilla.suse.com/show_bug.cgi?id=1230552
* https://bugzilla.suse.com/show_bug.cgi?id=1231345
Get the latest Linux and open source security news straight to your inbox.