* bsc#1222121 Cross-References: * CVE-2024-3019 . # Security update for pcp Announcement ID: SUSE-SU-2025:03233-1 Release Date: 2025-09-15T13:16:57Z Rating: important References: * bsc#1222121 Cross-References: * CVE-2024-3019 CVSS scores: * CVE-2024-3019 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves one vulnerability can now be installed. ## Description: This update for pcp fixes the following issues: * CVE-2024-3019: exposure of the redis server backend allows remote command execution via pmproxy (bsc#1222121). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-3233=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-3233=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-3233=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-3233=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-3233=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * pcp-import-collectl2pcp-5.2.2-150300.3.3.1 * pcp-pmda-apache-5.2.2-150300.3.3.1 * perl-PCP-MMV-5.2.2-150300.3.3.1 * pcp-zeroconf-5.2.2-150300.3.3.1 * pcp-pmda-named-5.2.2-150300.3.3.1 * libpcp_web1-debuginfo-5.2.2-150300.3.3.1 *pcp-pmda-memcache-5.2.2-150300.3.3.1 * pcp-export-pcp2json-5.2.2-150300.3.3.1 * python3-pcp-5.2.2-150300.3.3.1 * libpcp_gui2-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-cifs-5.2.2-150300.3.3.1 * pcp-devel-debuginfo-5.2.2-150300.3.3.1 * pcp-export-pcp2graphite-5.2.2-150300.3.3.1 * pcp-export-pcp2spark-5.2.2-150300.3.3.1 * pcp-pmda-gluster-5.2.2-150300.3.3.1 * pcp-pmda-rabbitmq-5.2.2-150300.3.3.1 * pcp-pmda-ds389-5.2.2-150300.3.3.1 * pcp-pmda-bash-5.2.2-150300.3.3.1 * libpcp-devel-5.2.2-150300.3.3.1 * pcp-pmda-zswap-5.2.2-150300.3.3.1 * pcp-pmda-sendmail-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-systemd-5.2.2-150300.3.3.1 * pcp-pmda-smart-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-bonding-5.2.2-150300.3.3.1 * pcp-pmda-nfsclient-5.2.2-150300.3.3.1 * perl-PCP-MMV-debuginfo-5.2.2-150300.3.3.1 * libpcp3-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-mailq-5.2.2-150300.3.3.1 * pcp-system-tools-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-LogImport-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-LogSummary-5.2.2-150300.3.3.1 * pcp-pmda-lustre-5.2.2-150300.3.3.1 * perl-PCP-LogImport-5.2.2-150300.3.3.1 * pcp-pmda-roomtemp-5.2.2-150300.3.3.1 * pcp-pmda-rpm-5.2.2-150300.3.3.1 * pcp-pmda-slurm-5.2.2-150300.3.3.1 * pcp-import-ganglia2pcp-5.2.2-150300.3.3.1 * perl-PCP-PMDA-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-smart-5.2.2-150300.3.3.1 * pcp-pmda-mic-5.2.2-150300.3.3.1 * pcp-pmda-oracle-5.2.2-150300.3.3.1 * pcp-pmda-logger-5.2.2-150300.3.3.1 * pcp-pmda-netcheck-5.2.2-150300.3.3.1 * pcp-import-collectl2pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-testsuite-5.2.2-150300.3.3.1 * pcp-pmda-shping-debuginfo-5.2.2-150300.3.3.1 * libpcp_gui2-5.2.2-150300.3.3.1 * pcp-pmda-openvswitch-5.2.2-150300.3.3.1 * pcp-pmda-elasticsearch-5.2.2-150300.3.3.1 * pcp-pmda-mounts-5.2.2-150300.3.3.1 * pcp-pmda-activemq-5.2.2-150300.3.3.1 * pcp-pmda-pdns-5.2.2-150300.3.3.1 * libpcp3-5.2.2-150300.3.3.1 *pcp-pmda-logger-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-trace-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-netfilter-5.2.2-150300.3.3.1 * pcp-pmda-docker-debuginfo-5.2.2-150300.3.3.1 * pcp-gui-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-docker-5.2.2-150300.3.3.1 * pcp-pmda-unbound-5.2.2-150300.3.3.1 * pcp-pmda-samba-5.2.2-150300.3.3.1 * libpcp_import1-5.2.2-150300.3.3.1 * pcp-pmda-bash-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-postfix-5.2.2-150300.3.3.1 * pcp-pmda-gpfs-5.2.2-150300.3.3.1 * pcp-import-sar2pcp-5.2.2-150300.3.3.1 * pcp-export-pcp2xml-5.2.2-150300.3.3.1 * pcp-pmda-bind2-5.2.2-150300.3.3.1 * libpcp_import1-debuginfo-5.2.2-150300.3.3.1 * pcp-conf-5.2.2-150300.3.3.1 * pcp-pmda-shping-5.2.2-150300.3.3.1 * perl-PCP-PMDA-5.2.2-150300.3.3.1 * pcp-pmda-news-5.2.2-150300.3.3.1 * libpcp_mmv1-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-lustrecomm-debuginfo-5.2.2-150300.3.3.1 * pcp-devel-5.2.2-150300.3.3.1 * pcp-pmda-rpm-debuginfo-5.2.2-150300.3.3.1 * libpcp_web1-5.2.2-150300.3.3.1 * pcp-pmda-gpsd-5.2.2-150300.3.3.1 * pcp-pmda-sendmail-5.2.2-150300.3.3.1 * pcp-pmda-lmsensors-5.2.2-150300.3.3.1 * pcp-pmda-nvidia-gpu-5.2.2-150300.3.3.1 * pcp-pmda-cisco-debuginfo-5.2.2-150300.3.3.1 * pcp-5.2.2-150300.3.3.1 * pcp-pmda-zimbra-5.2.2-150300.3.3.1 * pcp-export-pcp2elasticsearch-5.2.2-150300.3.3.1 * pcp-pmda-dm-5.2.2-150300.3.3.1 * pcp-pmda-mounts-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-cisco-5.2.2-150300.3.3.1 * pcp-pmda-trace-5.2.2-150300.3.3.1 * pcp-pmda-vmware-5.2.2-150300.3.3.1 * pcp-pmda-openmetrics-5.2.2-150300.3.3.1 * pcp-export-pcp2influxdb-5.2.2-150300.3.3.1 * pcp-testsuite-debuginfo-5.2.2-150300.3.3.1 * libpcp_trace2-debuginfo-5.2.2-150300.3.3.1 * pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-cifs-debuginfo-5.2.2-150300.3.3.1 * pcp-debugsource-5.2.2-150300.3.3.1 * python3-pcp-debuginfo-5.2.2-150300.3.3.1 *pcp-pmda-gfs2-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-lustrecomm-5.2.2-150300.3.3.1 * pcp-pmda-rsyslog-5.2.2-150300.3.3.1 * libpcp_trace2-5.2.2-150300.3.3.1 * pcp-pmda-nvidia-gpu-debuginfo-5.2.2-150300.3.3.1 * pcp-import-iostat2pcp-5.2.2-150300.3.3.1 * pcp-pmda-redis-5.2.2-150300.3.3.1 * pcp-pmda-ds389log-5.2.2-150300.3.3.1 * pcp-pmda-mailq-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-5.2.2-150300.3.3.1 * pcp-pmda-nutcracker-5.2.2-150300.3.3.1 * pcp-pmda-haproxy-5.2.2-150300.3.3.1 * pcp-pmda-dm-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-dbping-5.2.2-150300.3.3.1 * pcp-pmda-nginx-5.2.2-150300.3.3.1 * libpcp_mmv1-5.2.2-150300.3.3.1 * pcp-pmda-gfs2-5.2.2-150300.3.3.1 * pcp-pmda-roomtemp-debuginfo-5.2.2-150300.3.3.1 * pcp-export-pcp2zabbix-5.2.2-150300.3.3.1 * pcp-pmda-mysql-5.2.2-150300.3.3.1 * pcp-pmda-json-5.2.2-150300.3.3.1 * pcp-pmda-weblog-5.2.2-150300.3.3.1 * pcp-pmda-summary-5.2.2-150300.3.3.1 * pcp-import-mrtg2pcp-5.2.2-150300.3.3.1 * pcp-pmda-weblog-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-systemd-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-summary-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-apache-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-snmp-5.2.2-150300.3.3.1 * pcp-gui-5.2.2-150300.3.3.1 * openSUSE Leap 15.3 (noarch) * pcp-doc-5.2.2-150300.3.3.1 * openSUSE Leap 15.3 (aarch64 ppc64le x86_64 i586) * pcp-pmda-infiniband-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-perfevent-5.2.2-150300.3.3.1 * pcp-pmda-infiniband-5.2.2-150300.3.3.1 * pcp-pmda-perfevent-debuginfo-5.2.2-150300.3.3.1 * openSUSE Leap 15.3 (x86_64) * pcp-pmda-mssql-5.2.2-150300.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-import-sar2pcp-5.2.2-150300.3.3.1 * perl-PCP-LogImport-5.2.2-150300.3.3.1 * perl-PCP-MMV-5.2.2-150300.3.3.1 * libpcp_import1-debuginfo-5.2.2-150300.3.3.1 *libpcp_web1-debuginfo-5.2.2-150300.3.3.1 * pcp-debugsource-5.2.2-150300.3.3.1 * python3-pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-conf-5.2.2-150300.3.3.1 * perl-PCP-PMDA-5.2.2-150300.3.3.1 * libpcp_trace2-5.2.2-150300.3.3.1 * python3-pcp-5.2.2-150300.3.3.1 * libpcp_gui2-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-PMDA-debuginfo-5.2.2-150300.3.3.1 * pcp-import-iostat2pcp-5.2.2-150300.3.3.1 * libpcp_mmv1-debuginfo-5.2.2-150300.3.3.1 * pcp-devel-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-5.2.2-150300.3.3.1 * pcp-devel-5.2.2-150300.3.3.1 * libpcp_gui2-5.2.2-150300.3.3.1 * libpcp_web1-5.2.2-150300.3.3.1 * libpcp-devel-5.2.2-150300.3.3.1 * pcp-5.2.2-150300.3.3.1 * libpcp3-5.2.2-150300.3.3.1 * libpcp_mmv1-5.2.2-150300.3.3.1 * perl-PCP-MMV-debuginfo-5.2.2-150300.3.3.1 * libpcp3-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-LogImport-debuginfo-5.2.2-150300.3.3.1 * pcp-import-mrtg2pcp-5.2.2-150300.3.3.1 * libpcp_import1-5.2.2-150300.3.3.1 * perl-PCP-LogSummary-5.2.2-150300.3.3.1 * libpcp_trace2-debuginfo-5.2.2-150300.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * pcp-doc-5.2.2-150300.3.3.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-import-sar2pcp-5.2.2-150300.3.3.1 * perl-PCP-LogImport-5.2.2-150300.3.3.1 * perl-PCP-MMV-5.2.2-150300.3.3.1 * libpcp_import1-debuginfo-5.2.2-150300.3.3.1 * libpcp_web1-debuginfo-5.2.2-150300.3.3.1 * pcp-debugsource-5.2.2-150300.3.3.1 * python3-pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-conf-5.2.2-150300.3.3.1 * perl-PCP-PMDA-5.2.2-150300.3.3.1 * libpcp_trace2-5.2.2-150300.3.3.1 * python3-pcp-5.2.2-150300.3.3.1 * libpcp_gui2-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-PMDA-debuginfo-5.2.2-150300.3.3.1 * pcp-import-iostat2pcp-5.2.2-150300.3.3.1 *libpcp_mmv1-debuginfo-5.2.2-150300.3.3.1 * pcp-devel-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-5.2.2-150300.3.3.1 * pcp-devel-5.2.2-150300.3.3.1 * libpcp_gui2-5.2.2-150300.3.3.1 * libpcp_web1-5.2.2-150300.3.3.1 * libpcp-devel-5.2.2-150300.3.3.1 * pcp-5.2.2-150300.3.3.1 * libpcp3-5.2.2-150300.3.3.1 * libpcp_mmv1-5.2.2-150300.3.3.1 * perl-PCP-MMV-debuginfo-5.2.2-150300.3.3.1 * libpcp3-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-LogImport-debuginfo-5.2.2-150300.3.3.1 * pcp-import-mrtg2pcp-5.2.2-150300.3.3.1 * libpcp_import1-5.2.2-150300.3.3.1 * perl-PCP-LogSummary-5.2.2-150300.3.3.1 * libpcp_trace2-debuginfo-5.2.2-150300.3.3.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (noarch) * pcp-doc-5.2.2-150300.3.3.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le x86_64) * pcp-pmda-perfevent-5.2.2-150300.3.3.1 * pcp-pmda-perfevent-debuginfo-5.2.2-150300.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-import-sar2pcp-5.2.2-150300.3.3.1 * perl-PCP-LogImport-5.2.2-150300.3.3.1 * perl-PCP-MMV-5.2.2-150300.3.3.1 * libpcp_import1-debuginfo-5.2.2-150300.3.3.1 * libpcp_web1-debuginfo-5.2.2-150300.3.3.1 * pcp-debugsource-5.2.2-150300.3.3.1 * python3-pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-conf-5.2.2-150300.3.3.1 * perl-PCP-PMDA-5.2.2-150300.3.3.1 * libpcp_trace2-5.2.2-150300.3.3.1 * python3-pcp-5.2.2-150300.3.3.1 * libpcp_gui2-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-PMDA-debuginfo-5.2.2-150300.3.3.1 * pcp-import-iostat2pcp-5.2.2-150300.3.3.1 * libpcp_mmv1-debuginfo-5.2.2-150300.3.3.1 * pcp-devel-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-5.2.2-150300.3.3.1 * pcp-devel-5.2.2-150300.3.3.1 * libpcp_gui2-5.2.2-150300.3.3.1 * libpcp_web1-5.2.2-150300.3.3.1 * libpcp-devel-5.2.2-150300.3.3.1 * pcp-5.2.2-150300.3.3.1 *libpcp3-5.2.2-150300.3.3.1 * libpcp_mmv1-5.2.2-150300.3.3.1 * perl-PCP-MMV-debuginfo-5.2.2-150300.3.3.1 * libpcp3-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-LogImport-debuginfo-5.2.2-150300.3.3.1 * pcp-import-mrtg2pcp-5.2.2-150300.3.3.1 * libpcp_import1-5.2.2-150300.3.3.1 * perl-PCP-LogSummary-5.2.2-150300.3.3.1 * libpcp_trace2-debuginfo-5.2.2-150300.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * pcp-doc-5.2.2-150300.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le) * pcp-pmda-perfevent-5.2.2-150300.3.3.1 * pcp-pmda-perfevent-debuginfo-5.2.2-150300.3.3.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-import-sar2pcp-5.2.2-150300.3.3.1 * perl-PCP-LogImport-5.2.2-150300.3.3.1 * perl-PCP-MMV-5.2.2-150300.3.3.1 * libpcp_import1-debuginfo-5.2.2-150300.3.3.1 * libpcp_web1-debuginfo-5.2.2-150300.3.3.1 * pcp-debugsource-5.2.2-150300.3.3.1 * python3-pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-conf-5.2.2-150300.3.3.1 * perl-PCP-PMDA-5.2.2-150300.3.3.1 * libpcp_trace2-5.2.2-150300.3.3.1 * python3-pcp-5.2.2-150300.3.3.1 * libpcp_gui2-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-PMDA-debuginfo-5.2.2-150300.3.3.1 * pcp-import-iostat2pcp-5.2.2-150300.3.3.1 * libpcp_mmv1-debuginfo-5.2.2-150300.3.3.1 * pcp-devel-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-5.2.2-150300.3.3.1 * pcp-devel-5.2.2-150300.3.3.1 * libpcp_gui2-5.2.2-150300.3.3.1 * libpcp_web1-5.2.2-150300.3.3.1 * libpcp-devel-5.2.2-150300.3.3.1 * pcp-5.2.2-150300.3.3.1 * libpcp3-5.2.2-150300.3.3.1 * libpcp_mmv1-5.2.2-150300.3.3.1 * pcp-pmda-perfevent-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-MMV-debuginfo-5.2.2-150300.3.3.1 * libpcp3-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-LogImport-debuginfo-5.2.2-150300.3.3.1 *pcp-import-mrtg2pcp-5.2.2-150300.3.3.1 * libpcp_import1-5.2.2-150300.3.3.1 * perl-PCP-LogSummary-5.2.2-150300.3.3.1 * pcp-pmda-perfevent-5.2.2-150300.3.3.1 * libpcp_trace2-debuginfo-5.2.2-150300.3.3.1 * SUSE Enterprise Storage 7.1 (noarch) * pcp-doc-5.2.2-150300.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-3019.html * https://bugzilla.suse.com/show_bug.cgi?id=1222121 . The patch addressing CVE-2024-3019 in pcp provides crucial security enhancements for impacted SUSE environments, mitigating risks associated with unauthorized remote command execution.. SUSE security update, pcp command execution, important patches. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for pcp Announcement ID: SUSE-SU-2025:03233-1 Release Date: 2025-09-15T13:16:57Z Rating: important References: * bsc#1222121 Cross-References: * CVE-2024-3019 CVSS scores: * CVE-2024-3019 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves one vulnerability can now be installed. ## Description: This update for pcp fixes the following issues: * CVE-2024-3019: exposure of the redis server backend allows remote command execution via pmproxy (bsc#1222121). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-3233=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2025-3233=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2025-3233=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-3233=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2025-3233=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * pcp-import-collectl2pcp-5.2.2-150300.3.3.1 * pcp-pmda-apache-5.2.2-150300.3.3.1 * perl-PCP-MMV-5.2.2-150300.3.3.1 * pcp-zeroconf-5.2.2-150300.3.3.1 * pcp-pmda-named-5.2.2-150300.3.3.1 * libpcp_web1-debuginfo-5.2.2-150300.3.3.1 *pcp-pmda-memcache-5.2.2-150300.3.3.1 * pcp-export-pcp2json-5.2.2-150300.3.3.1 * python3-pcp-5.2.2-150300.3.3.1 * libpcp_gui2-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-cifs-5.2.2-150300.3.3.1 * pcp-devel-debuginfo-5.2.2-150300.3.3.1 * pcp-export-pcp2graphite-5.2.2-150300.3.3.1 * pcp-export-pcp2spark-5.2.2-150300.3.3.1 * pcp-pmda-gluster-5.2.2-150300.3.3.1 * pcp-pmda-rabbitmq-5.2.2-150300.3.3.1 * pcp-pmda-ds389-5.2.2-150300.3.3.1 * pcp-pmda-bash-5.2.2-150300.3.3.1 * libpcp-devel-5.2.2-150300.3.3.1 * pcp-pmda-zswap-5.2.2-150300.3.3.1 * pcp-pmda-sendmail-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-systemd-5.2.2-150300.3.3.1 * pcp-pmda-smart-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-bonding-5.2.2-150300.3.3.1 * pcp-pmda-nfsclient-5.2.2-150300.3.3.1 * perl-PCP-MMV-debuginfo-5.2.2-150300.3.3.1 * libpcp3-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-mailq-5.2.2-150300.3.3.1 * pcp-system-tools-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-LogImport-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-LogSummary-5.2.2-150300.3.3.1 * pcp-pmda-lustre-5.2.2-150300.3.3.1 * perl-PCP-LogImport-5.2.2-150300.3.3.1 * pcp-pmda-roomtemp-5.2.2-150300.3.3.1 * pcp-pmda-rpm-5.2.2-150300.3.3.1 * pcp-pmda-slurm-5.2.2-150300.3.3.1 * pcp-import-ganglia2pcp-5.2.2-150300.3.3.1 * perl-PCP-PMDA-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-smart-5.2.2-150300.3.3.1 * pcp-pmda-mic-5.2.2-150300.3.3.1 * pcp-pmda-oracle-5.2.2-150300.3.3.1 * pcp-pmda-logger-5.2.2-150300.3.3.1 * pcp-pmda-netcheck-5.2.2-150300.3.3.1 * pcp-import-collectl2pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-testsuite-5.2.2-150300.3.3.1 * pcp-pmda-shping-debuginfo-5.2.2-150300.3.3.1 * libpcp_gui2-5.2.2-150300.3.3.1 * pcp-pmda-openvswitch-5.2.2-150300.3.3.1 * pcp-pmda-elasticsearch-5.2.2-150300.3.3.1 * pcp-pmda-mounts-5.2.2-150300.3.3.1 * pcp-pmda-activemq-5.2.2-150300.3.3.1 * pcp-pmda-pdns-5.2.2-150300.3.3.1 * libpcp3-5.2.2-150300.3.3.1 *pcp-pmda-logger-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-trace-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-netfilter-5.2.2-150300.3.3.1 * pcp-pmda-docker-debuginfo-5.2.2-150300.3.3.1 * pcp-gui-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-docker-5.2.2-150300.3.3.1 * pcp-pmda-unbound-5.2.2-150300.3.3.1 * pcp-pmda-samba-5.2.2-150300.3.3.1 * libpcp_import1-5.2.2-150300.3.3.1 * pcp-pmda-bash-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-postfix-5.2.2-150300.3.3.1 * pcp-pmda-gpfs-5.2.2-150300.3.3.1 * pcp-import-sar2pcp-5.2.2-150300.3.3.1 * pcp-export-pcp2xml-5.2.2-150300.3.3.1 * pcp-pmda-bind2-5.2.2-150300.3.3.1 * libpcp_import1-debuginfo-5.2.2-150300.3.3.1 * pcp-conf-5.2.2-150300.3.3.1 * pcp-pmda-shping-5.2.2-150300.3.3.1 * perl-PCP-PMDA-5.2.2-150300.3.3.1 * pcp-pmda-news-5.2.2-150300.3.3.1 * libpcp_mmv1-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-lustrecomm-debuginfo-5.2.2-150300.3.3.1 * pcp-devel-5.2.2-150300.3.3.1 * pcp-pmda-rpm-debuginfo-5.2.2-150300.3.3.1 * libpcp_web1-5.2.2-150300.3.3.1 * pcp-pmda-gpsd-5.2.2-150300.3.3.1 * pcp-pmda-sendmail-5.2.2-150300.3.3.1 * pcp-pmda-lmsensors-5.2.2-150300.3.3.1 * pcp-pmda-nvidia-gpu-5.2.2-150300.3.3.1 * pcp-pmda-cisco-debuginfo-5.2.2-150300.3.3.1 * pcp-5.2.2-150300.3.3.1 * pcp-pmda-zimbra-5.2.2-150300.3.3.1 * pcp-export-pcp2elasticsearch-5.2.2-150300.3.3.1 * pcp-pmda-dm-5.2.2-150300.3.3.1 * pcp-pmda-mounts-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-cisco-5.2.2-150300.3.3.1 * pcp-pmda-trace-5.2.2-150300.3.3.1 * pcp-pmda-vmware-5.2.2-150300.3.3.1 * pcp-pmda-openmetrics-5.2.2-150300.3.3.1 * pcp-export-pcp2influxdb-5.2.2-150300.3.3.1 * pcp-testsuite-debuginfo-5.2.2-150300.3.3.1 * libpcp_trace2-debuginfo-5.2.2-150300.3.3.1 * pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-cifs-debuginfo-5.2.2-150300.3.3.1 * pcp-debugsource-5.2.2-150300.3.3.1 * python3-pcp-debuginfo-5.2.2-150300.3.3.1 *pcp-pmda-gfs2-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-lustrecomm-5.2.2-150300.3.3.1 * pcp-pmda-rsyslog-5.2.2-150300.3.3.1 * libpcp_trace2-5.2.2-150300.3.3.1 * pcp-pmda-nvidia-gpu-debuginfo-5.2.2-150300.3.3.1 * pcp-import-iostat2pcp-5.2.2-150300.3.3.1 * pcp-pmda-redis-5.2.2-150300.3.3.1 * pcp-pmda-ds389log-5.2.2-150300.3.3.1 * pcp-pmda-mailq-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-5.2.2-150300.3.3.1 * pcp-pmda-nutcracker-5.2.2-150300.3.3.1 * pcp-pmda-haproxy-5.2.2-150300.3.3.1 * pcp-pmda-dm-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-dbping-5.2.2-150300.3.3.1 * pcp-pmda-nginx-5.2.2-150300.3.3.1 * libpcp_mmv1-5.2.2-150300.3.3.1 * pcp-pmda-gfs2-5.2.2-150300.3.3.1 * pcp-pmda-roomtemp-debuginfo-5.2.2-150300.3.3.1 * pcp-export-pcp2zabbix-5.2.2-150300.3.3.1 * pcp-pmda-mysql-5.2.2-150300.3.3.1 * pcp-pmda-json-5.2.2-150300.3.3.1 * pcp-pmda-weblog-5.2.2-150300.3.3.1 * pcp-pmda-summary-5.2.2-150300.3.3.1 * pcp-import-mrtg2pcp-5.2.2-150300.3.3.1 * pcp-pmda-weblog-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-systemd-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-summary-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-apache-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-snmp-5.2.2-150300.3.3.1 * pcp-gui-5.2.2-150300.3.3.1 * openSUSE Leap 15.3 (noarch) * pcp-doc-5.2.2-150300.3.3.1 * openSUSE Leap 15.3 (aarch64 ppc64le x86_64 i586) * pcp-pmda-infiniband-debuginfo-5.2.2-150300.3.3.1 * pcp-pmda-perfevent-5.2.2-150300.3.3.1 * pcp-pmda-infiniband-5.2.2-150300.3.3.1 * pcp-pmda-perfevent-debuginfo-5.2.2-150300.3.3.1 * openSUSE Leap 15.3 (x86_64) * pcp-pmda-mssql-5.2.2-150300.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-import-sar2pcp-5.2.2-150300.3.3.1 * perl-PCP-LogImport-5.2.2-150300.3.3.1 * perl-PCP-MMV-5.2.2-150300.3.3.1 * libpcp_import1-debuginfo-5.2.2-150300.3.3.1 *libpcp_web1-debuginfo-5.2.2-150300.3.3.1 * pcp-debugsource-5.2.2-150300.3.3.1 * python3-pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-conf-5.2.2-150300.3.3.1 * perl-PCP-PMDA-5.2.2-150300.3.3.1 * libpcp_trace2-5.2.2-150300.3.3.1 * python3-pcp-5.2.2-150300.3.3.1 * libpcp_gui2-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-PMDA-debuginfo-5.2.2-150300.3.3.1 * pcp-import-iostat2pcp-5.2.2-150300.3.3.1 * libpcp_mmv1-debuginfo-5.2.2-150300.3.3.1 * pcp-devel-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-5.2.2-150300.3.3.1 * pcp-devel-5.2.2-150300.3.3.1 * libpcp_gui2-5.2.2-150300.3.3.1 * libpcp_web1-5.2.2-150300.3.3.1 * libpcp-devel-5.2.2-150300.3.3.1 * pcp-5.2.2-150300.3.3.1 * libpcp3-5.2.2-150300.3.3.1 * libpcp_mmv1-5.2.2-150300.3.3.1 * perl-PCP-MMV-debuginfo-5.2.2-150300.3.3.1 * libpcp3-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-LogImport-debuginfo-5.2.2-150300.3.3.1 * pcp-import-mrtg2pcp-5.2.2-150300.3.3.1 * libpcp_import1-5.2.2-150300.3.3.1 * perl-PCP-LogSummary-5.2.2-150300.3.3.1 * libpcp_trace2-debuginfo-5.2.2-150300.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * pcp-doc-5.2.2-150300.3.3.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-import-sar2pcp-5.2.2-150300.3.3.1 * perl-PCP-LogImport-5.2.2-150300.3.3.1 * perl-PCP-MMV-5.2.2-150300.3.3.1 * libpcp_import1-debuginfo-5.2.2-150300.3.3.1 * libpcp_web1-debuginfo-5.2.2-150300.3.3.1 * pcp-debugsource-5.2.2-150300.3.3.1 * python3-pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-conf-5.2.2-150300.3.3.1 * perl-PCP-PMDA-5.2.2-150300.3.3.1 * libpcp_trace2-5.2.2-150300.3.3.1 * python3-pcp-5.2.2-150300.3.3.1 * libpcp_gui2-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-PMDA-debuginfo-5.2.2-150300.3.3.1 * pcp-import-iostat2pcp-5.2.2-150300.3.3.1 *libpcp_mmv1-debuginfo-5.2.2-150300.3.3.1 * pcp-devel-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-5.2.2-150300.3.3.1 * pcp-devel-5.2.2-150300.3.3.1 * libpcp_gui2-5.2.2-150300.3.3.1 * libpcp_web1-5.2.2-150300.3.3.1 * libpcp-devel-5.2.2-150300.3.3.1 * pcp-5.2.2-150300.3.3.1 * libpcp3-5.2.2-150300.3.3.1 * libpcp_mmv1-5.2.2-150300.3.3.1 * perl-PCP-MMV-debuginfo-5.2.2-150300.3.3.1 * libpcp3-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-LogImport-debuginfo-5.2.2-150300.3.3.1 * pcp-import-mrtg2pcp-5.2.2-150300.3.3.1 * libpcp_import1-5.2.2-150300.3.3.1 * perl-PCP-LogSummary-5.2.2-150300.3.3.1 * libpcp_trace2-debuginfo-5.2.2-150300.3.3.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (noarch) * pcp-doc-5.2.2-150300.3.3.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le x86_64) * pcp-pmda-perfevent-5.2.2-150300.3.3.1 * pcp-pmda-perfevent-debuginfo-5.2.2-150300.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-import-sar2pcp-5.2.2-150300.3.3.1 * perl-PCP-LogImport-5.2.2-150300.3.3.1 * perl-PCP-MMV-5.2.2-150300.3.3.1 * libpcp_import1-debuginfo-5.2.2-150300.3.3.1 * libpcp_web1-debuginfo-5.2.2-150300.3.3.1 * pcp-debugsource-5.2.2-150300.3.3.1 * python3-pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-conf-5.2.2-150300.3.3.1 * perl-PCP-PMDA-5.2.2-150300.3.3.1 * libpcp_trace2-5.2.2-150300.3.3.1 * python3-pcp-5.2.2-150300.3.3.1 * libpcp_gui2-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-PMDA-debuginfo-5.2.2-150300.3.3.1 * pcp-import-iostat2pcp-5.2.2-150300.3.3.1 * libpcp_mmv1-debuginfo-5.2.2-150300.3.3.1 * pcp-devel-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-5.2.2-150300.3.3.1 * pcp-devel-5.2.2-150300.3.3.1 * libpcp_gui2-5.2.2-150300.3.3.1 * libpcp_web1-5.2.2-150300.3.3.1 * libpcp-devel-5.2.2-150300.3.3.1 * pcp-5.2.2-150300.3.3.1 *libpcp3-5.2.2-150300.3.3.1 * libpcp_mmv1-5.2.2-150300.3.3.1 * perl-PCP-MMV-debuginfo-5.2.2-150300.3.3.1 * libpcp3-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-LogImport-debuginfo-5.2.2-150300.3.3.1 * pcp-import-mrtg2pcp-5.2.2-150300.3.3.1 * libpcp_import1-5.2.2-150300.3.3.1 * perl-PCP-LogSummary-5.2.2-150300.3.3.1 * libpcp_trace2-debuginfo-5.2.2-150300.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * pcp-doc-5.2.2-150300.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le) * pcp-pmda-perfevent-5.2.2-150300.3.3.1 * pcp-pmda-perfevent-debuginfo-5.2.2-150300.3.3.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-import-sar2pcp-5.2.2-150300.3.3.1 * perl-PCP-LogImport-5.2.2-150300.3.3.1 * perl-PCP-MMV-5.2.2-150300.3.3.1 * libpcp_import1-debuginfo-5.2.2-150300.3.3.1 * libpcp_web1-debuginfo-5.2.2-150300.3.3.1 * pcp-debugsource-5.2.2-150300.3.3.1 * python3-pcp-debuginfo-5.2.2-150300.3.3.1 * pcp-conf-5.2.2-150300.3.3.1 * perl-PCP-PMDA-5.2.2-150300.3.3.1 * libpcp_trace2-5.2.2-150300.3.3.1 * python3-pcp-5.2.2-150300.3.3.1 * libpcp_gui2-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-PMDA-debuginfo-5.2.2-150300.3.3.1 * pcp-import-iostat2pcp-5.2.2-150300.3.3.1 * libpcp_mmv1-debuginfo-5.2.2-150300.3.3.1 * pcp-devel-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-5.2.2-150300.3.3.1 * pcp-devel-5.2.2-150300.3.3.1 * libpcp_gui2-5.2.2-150300.3.3.1 * libpcp_web1-5.2.2-150300.3.3.1 * libpcp-devel-5.2.2-150300.3.3.1 * pcp-5.2.2-150300.3.3.1 * libpcp3-5.2.2-150300.3.3.1 * libpcp_mmv1-5.2.2-150300.3.3.1 * pcp-pmda-perfevent-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-MMV-debuginfo-5.2.2-150300.3.3.1 * libpcp3-debuginfo-5.2.2-150300.3.3.1 * pcp-system-tools-debuginfo-5.2.2-150300.3.3.1 * perl-PCP-LogImport-debuginfo-5.2.2-150300.3.3.1 *pcp-import-mrtg2pcp-5.2.2-150300.3.3.1 * libpcp_import1-5.2.2-150300.3.3.1 * perl-PCP-LogSummary-5.2.2-150300.3.3.1 * pcp-pmda-perfevent-5.2.2-150300.3.3.1 * libpcp_trace2-debuginfo-5.2.2-150300.3.3.1 * SUSE Enterprise Storage 7.1 (noarch) * pcp-doc-5.2.2-150300.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-3019.html * https://bugzilla.suse.com/show_bug.cgi?id=1222121 . Patch released for pcp vulnerabilities CVE-2024-3019 enabling remote command execution in openSUSE, classified as critical.. pcp security update, remote execution patch, openSUSE advisory. . Severity: Important. LinuxSecurity.com Team
* bsc#1069468 * bsc#1217783 * bsc#1217826 * bsc#1222121 * bsc#1222815 . # Security update for pcp Announcement ID: SUSE-SU-2025:20133-1 Release Date: 2025-03-05T15:58:43Z Rating: important References: * bsc#1069468 * bsc#1217783 * bsc#1217826 * bsc#1222121 * bsc#1222815 * bsc#1230551 * bsc#1230552 Cross-References: * CVE-2023-6917 * CVE-2024-3019 * CVE-2024-45769 * CVE-2024-45770 CVSS scores: * CVE-2023-6917 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6917 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2023-6917 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-3019 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45769 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-45769 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45769 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45770 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2024-45770 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2024-45770 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities and has three fixes can now be installed. ## Description: This update for pcp fixes the following issues: * CVE-2024-45770: Fixed `pmpost` symlink attack allowing escalating `pcp` to `root` user (bsc#1230552). * CVE-2024-45769: Fixed `pmcd` heap corruption through metric pmstore operations (bsc#1230551). * CVE-2024-3019: Fixed exposure of the redis backend server allowing remote command execution via pmproxy (bsc#1222121). * CVE-2023-6917: Fixed Local privilege escalation from pcp user to root in /usr/libexec/pcp/lib/pmproxy (bsc#1217826). Other fixes: \- Updated to version 6.2.0 ## Patch Instructions: To install this SUSE update use the SUSErecommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-222=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libpcp3-debuginfo-6.2.0-1.1 * pcp-debugsource-6.2.0-1.1 * libpcp_import1-debuginfo-6.2.0-1.1 * libpcp_import1-6.2.0-1.1 * libpcp3-6.2.0-1.1 * SUSE Linux Micro 6.0 (noarch) * pcp-conf-6.2.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2023-6917.html * https://www.suse.com/security/cve/CVE-2024-3019.html * https://www.suse.com/security/cve/CVE-2024-45769.html * https://www.suse.com/security/cve/CVE-2024-45770.html * https://bugzilla.suse.com/show_bug.cgi?id=1069468 * https://bugzilla.suse.com/show_bug.cgi?id=1217783 * https://bugzilla.suse.com/show_bug.cgi?id=1217826 * https://bugzilla.suse.com/show_bug.cgi?id=1222121 * https://bugzilla.suse.com/show_bug.cgi?id=1222815 * https://bugzilla.suse.com/show_bug.cgi?id=1230551 * https://bugzilla.suse.com/show_bug.cgi?id=1230552 . SUSE has issued a security advisory addressing severe pcp flaws affecting version 6.0. Ensure you implement the necessary patches immediately!. SUSE Linux Micro, pcp update, remote execution, security patch. . Severity: Important. LinuxSecurity.com Team
* bsc#1069468 * bsc#1217783 * bsc#1217826 * bsc#1222121 * bsc#1222815 . # Security update for pcp Announcement ID: SUSE-SU-2025:20133-1 Release Date: 2025-03-05T15:58:43Z Rating: important References: * bsc#1069468 * bsc#1217783 * bsc#1217826 * bsc#1222121 * bsc#1222815 * bsc#1230551 * bsc#1230552 Cross-References: * CVE-2023-6917 * CVE-2024-3019 * CVE-2024-45769 * CVE-2024-45770 CVSS scores: * CVE-2023-6917 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6917 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2023-6917 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-3019 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45769 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-45769 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45769 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45770 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2024-45770 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2024-45770 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities and has three fixes can now be installed. ## Description: This update for pcp fixes the following issues: * CVE-2024-45770: Fixed `pmpost` symlink attack allowing escalating `pcp` to `root` user (bsc#1230552). * CVE-2024-45769: Fixed `pmcd` heap corruption through metric pmstore operations (bsc#1230551). * CVE-2024-3019: Fixed exposure of the redis backend server allowing remote command execution via pmproxy (bsc#1222121). * CVE-2023-6917: Fixed Local privilege escalation from pcp user to root in /usr/libexec/pcp/lib/pmproxy (bsc#1217826). Other fixes: \- Updated to version 6.2.0 ## Patch Instructions: To install this SUSE update use the SUSErecommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-222=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libpcp3-6.2.0-1.1 * pcp-debugsource-6.2.0-1.1 * libpcp3-debuginfo-6.2.0-1.1 * libpcp_import1-6.2.0-1.1 * libpcp_import1-debuginfo-6.2.0-1.1 * SUSE Linux Micro 6.0 (noarch) * pcp-conf-6.2.0-1.1 ## References: * https://www.suse.com/security/cve/CVE-2023-6917.html * https://www.suse.com/security/cve/CVE-2024-3019.html * https://www.suse.com/security/cve/CVE-2024-45769.html * https://www.suse.com/security/cve/CVE-2024-45770.html * https://bugzilla.suse.com/show_bug.cgi?id=1069468 * https://bugzilla.suse.com/show_bug.cgi?id=1217783 * https://bugzilla.suse.com/show_bug.cgi?id=1217826 * https://bugzilla.suse.com/show_bug.cgi?id=1222121 * https://bugzilla.suse.com/show_bug.cgi?id=1222815 * https://bugzilla.suse.com/show_bug.cgi?id=1230551 * https://bugzilla.suse.com/show_bug.cgi?id=1230552 . SUSE Linux Micro has released urgent patches addressing several pcp security flaws, particularly issues related to remote command execution vulnerabilities.. pcp security,SUSE update,remote execution fix,local escalation. . Severity: Important. LinuxSecurity.com Team
* bsc#1217783 * bsc#1217826 * bsc#1222121 * bsc#1230551 * bsc#1230552 . # Security update for pcp Announcement ID: SUSE-SU-2025:20235-1 Release Date: 2025-03-07T16:42:41Z Rating: moderate References: * bsc#1217783 * bsc#1217826 * bsc#1222121 * bsc#1230551 * bsc#1230552 Cross-References: * CVE-2023-6917 * CVE-2024-3019 * CVE-2024-45769 * CVE-2024-45770 CVSS scores: * CVE-2023-6917 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2023-6917 ( NVD ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2023-6917 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-3019 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45769 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-45769 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45769 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45770 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2024-45770 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2024-45770 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities and has one fix can now be installed. ## Description: This update for pcp fixes the following issues: * CVE-2024-45769: Fixed `pmcd` heap corruption through metric pmstore operations (bsc#1230551). * CVE-2024-45770: Fixed `pmpost` symlink attack allowing escalating `pcp` to `root` user (bsc#1230552). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-33=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) *libpcp_import1-6.2.0-slfo.1.1_3.1 * libpcp_import1-debuginfo-6.2.0-slfo.1.1_3.1 * libpcp3-6.2.0-slfo.1.1_3.1 * pcp-debugsource-6.2.0-slfo.1.1_3.1 * libpcp3-debuginfo-6.2.0-slfo.1.1_3.1 * SUSE Linux Micro 6.1 (noarch) * pcp-conf-6.2.0-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-6917.html * https://www.suse.com/security/cve/CVE-2024-3019.html * https://www.suse.com/security/cve/CVE-2024-45769.html * https://www.suse.com/security/cve/CVE-2024-45770.html * https://bugzilla.suse.com/show_bug.cgi?id=1217783 * https://bugzilla.suse.com/show_bug.cgi?id=1217826 * https://bugzilla.suse.com/show_bug.cgi?id=1222121 * https://bugzilla.suse.com/show_bug.cgi?id=1230551 * https://bugzilla.suse.com/show_bug.cgi?id=1230552 . Crucial patch released for SUSE Linux Micro 6.1 tackling various severe vulnerabilities in pcp.. SUSE Linux Micro, pcp security, moderate patch, Linux updates. . LinuxSecurity.com Team
* bsc#1217826 * bsc#1222815 Cross-References: * CVE-2023-6917 . # Security update for pcp Announcement ID: SUSE-SU-2025:0801-1 Release Date: 2025-03-06T14:04:47Z Rating: moderate References: * bsc#1217826 * bsc#1222815 Cross-References: * CVE-2023-6917 CVSS scores: * CVE-2023-6917 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for pcp fixes the following issues: * Version upgrade 6.2.0 (bsc#1217826, PED#8192, CVE-2023-6917). * Performance CoPilot 6 is not starting due to missing pmlogger_daily.timer (bsc#1222815). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-801=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-801=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-801=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-801=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-801=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * perl-PCP-LogSummary-6.2.0-150400.5.12.3 * pcp-system-tools-6.2.0-150400.5.12.3 *perl-PCP-PMDA-debuginfo-6.2.0-150400.5.12.3 * pcp-devel-6.2.0-150400.5.12.3 * pcp-pmda-logger-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-cifs-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-sendmail-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-hacluster-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-shping-debuginfo-6.2.0-150400.5.12.3 * libpcp_mmv1-6.2.0-150400.5.12.3 * libpcp_trace2-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-cifs-6.2.0-150400.5.12.3 * pcp-pmda-cisco-debuginfo-6.2.0-150400.5.12.3 * pcp-gui-6.2.0-150400.5.12.3 * pcp-pmda-hacluster-6.2.0-150400.5.12.3 * pcp-pmda-mailq-debuginfo-6.2.0-150400.5.12.3 * pcp-debugsource-6.2.0-150400.5.12.3 * libpcp3-6.2.0-150400.5.12.3 * pcp-pmda-mounts-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-apache-6.2.0-150400.5.12.3 * pcp-pmda-summary-6.2.0-150400.5.12.3 * pcp-pmda-weblog-6.2.0-150400.5.12.3 * perl-PCP-PMDA-6.2.0-150400.5.12.3 * libpcp3-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-zimbra-6.2.0-150400.5.12.3 * libpcp_gui2-6.2.0-150400.5.12.3 * pcp-devel-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-systemd-6.2.0-150400.5.12.3 * pcp-pmda-weblog-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.12.3 * libpcp_mmv1-debuginfo-6.2.0-150400.5.12.3 * libpcp-devel-6.2.0-150400.5.12.3 * pcp-import-collectl2pcp-6.2.0-150400.5.12.3 * pcp-pmda-summary-debuginfo-6.2.0-150400.5.12.3 * pcp-testsuite-debuginfo-6.2.0-150400.5.12.3 * pcp-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-mailq-6.2.0-150400.5.12.3 * pcp-pmda-gfs2-6.2.0-150400.5.12.3 * pcp-pmda-systemd-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-gfs2-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-shping-6.2.0-150400.5.12.3 * pcp-6.2.0-150400.5.12.3 * perl-PCP-LogImport-6.2.0-150400.5.12.3 * libpcp_gui2-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-bash-6.2.0-150400.5.12.3 * perl-PCP-MMV-6.2.0-150400.5.12.3 *pcp-pmda-smart-6.2.0-150400.5.12.3 * pcp-pmda-dm-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-sendmail-6.2.0-150400.5.12.3 * pcp-gui-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-bind2-6.2.0-150400.5.12.3 * pcp-pmda-dm-6.2.0-150400.5.12.3 * pcp-pmda-smart-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-bash-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-6.2.0-150400.5.12.3 * pcp-pmda-nvidia-gpu-debuginfo-6.2.0-150400.5.12.3 * python3-pcp-6.2.0-150400.5.12.3 * pcp-pmda-lustrecomm-debuginfo-6.2.0-150400.5.12.3 * pcp-system-tools-debuginfo-6.2.0-150400.5.12.3 * python3-pcp-debuginfo-6.2.0-150400.5.12.3 * pcp-testsuite-6.2.0-150400.5.12.3 * pcp-import-collectl2pcp-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-apache-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-roomtemp-6.2.0-150400.5.12.3 * pcp-pmda-sockets-6.2.0-150400.5.12.3 * libpcp_trace2-6.2.0-150400.5.12.3 * pcp-pmda-logger-6.2.0-150400.5.12.3 * pcp-pmda-lustrecomm-6.2.0-150400.5.12.3 * libpcp_web1-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-trace-6.2.0-150400.5.12.3 * pcp-pmda-sockets-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-cisco-6.2.0-150400.5.12.3 * pcp-pmda-mounts-6.2.0-150400.5.12.3 * pcp-pmda-roomtemp-debuginfo-6.2.0-150400.5.12.3 * libpcp_web1-6.2.0-150400.5.12.3 * pcp-pmda-trace-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-nvidia-gpu-6.2.0-150400.5.12.3 * pcp-pmda-zimbra-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-docker-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-docker-6.2.0-150400.5.12.3 * openSUSE Leap 15.4 (noarch) * pcp-pmda-json-6.2.0-150400.5.12.3 * pcp-export-pcp2spark-6.2.0-150400.5.12.3 * pcp-conf-6.2.0-150400.5.12.3 * pcp-export-pcp2elasticsearch-6.2.0-150400.5.12.3 * pcp-pmda-haproxy-6.2.0-150400.5.12.3 * pcp-export-pcp2zabbix-6.2.0-150400.5.12.3 * pcp-export-pcp2graphite-6.2.0-150400.5.12.3 * pcp-pmda-slurm-6.2.0-150400.5.12.3 *pcp-pmda-netcheck-6.2.0-150400.5.12.3 * pcp-pmda-lmsensors-6.2.0-150400.5.12.3 * pcp-pmda-lustre-6.2.0-150400.5.12.3 * pcp-pmda-rabbitmq-6.2.0-150400.5.12.3 * pcp-pmda-memcache-6.2.0-150400.5.12.3 * pcp-pmda-oracle-6.2.0-150400.5.12.3 * pcp-pmda-ds389log-6.2.0-150400.5.12.3 * pcp-pmda-openmetrics-6.2.0-150400.5.12.3 * pcp-pmda-gpfs-6.2.0-150400.5.12.3 * pcp-export-pcp2influxdb-6.2.0-150400.5.12.3 * pcp-pmda-bonding-6.2.0-150400.5.12.3 * pcp-import-ganglia2pcp-6.2.0-150400.5.12.3 * pcp-pmda-mysql-6.2.0-150400.5.12.3 * pcp-pmda-ds389-6.2.0-150400.5.12.3 * pcp-pmda-unbound-6.2.0-150400.5.12.3 * pcp-export-pcp2xml-6.2.0-150400.5.12.3 * pcp-pmda-news-6.2.0-150400.5.12.3 * pcp-pmda-zswap-6.2.0-150400.5.12.3 * pcp-pmda-samba-6.2.0-150400.5.12.3 * pcp-pmda-rsyslog-6.2.0-150400.5.12.3 * pcp-import-mrtg2pcp-6.2.0-150400.5.12.3 * pcp-pmda-postfix-6.2.0-150400.5.12.3 * pcp-pmda-snmp-6.2.0-150400.5.12.3 * pcp-pmda-named-6.2.0-150400.5.12.3 * pcp-pmda-activemq-6.2.0-150400.5.12.3 * pcp-pmda-nutcracker-6.2.0-150400.5.12.3 * pcp-doc-6.2.0-150400.5.12.3 * pcp-pmda-nfsclient-6.2.0-150400.5.12.3 * pcp-pmda-openvswitch-6.2.0-150400.5.12.3 * pcp-import-sar2pcp-6.2.0-150400.5.12.3 * pcp-pmda-gpsd-6.2.0-150400.5.12.3 * pcp-pmda-netfilter-6.2.0-150400.5.12.3 * pcp-pmda-pdns-6.2.0-150400.5.12.3 * pcp-pmda-mic-6.2.0-150400.5.12.3 * pcp-zeroconf-6.2.0-150400.5.12.3 * pcp-pmda-dbping-6.2.0-150400.5.12.3 * pcp-import-iostat2pcp-6.2.0-150400.5.12.3 * pcp-pmda-gluster-6.2.0-150400.5.12.3 * pcp-pmda-redis-6.2.0-150400.5.12.3 * pcp-pmda-nginx-6.2.0-150400.5.12.3 * pcp-pmda-elasticsearch-6.2.0-150400.5.12.3 * pcp-export-pcp2json-6.2.0-150400.5.12.3 * openSUSE Leap 15.4 (aarch64 ppc64le x86_64 i586) * pcp-pmda-infiniband-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-perfevent-6.2.0-150400.5.12.3 * pcp-pmda-perfevent-debuginfo-6.2.0-150400.5.12.3 *pcp-pmda-infiniband-6.2.0-150400.5.12.3 * openSUSE Leap 15.4 (x86_64) * pcp-pmda-resctrl-6.2.0-150400.5.12.3 * pcp-pmda-resctrl-debuginfo-6.2.0-150400.5.12.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * pcp-system-tools-6.2.0-150400.5.12.3 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.12.3 * pcp-devel-6.2.0-150400.5.12.3 * libpcp_mmv1-6.2.0-150400.5.12.3 * libpcp_trace2-debuginfo-6.2.0-150400.5.12.3 * pcp-debugsource-6.2.0-150400.5.12.3 * libpcp3-6.2.0-150400.5.12.3 * perl-PCP-PMDA-6.2.0-150400.5.12.3 * libpcp3-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-debuginfo-6.2.0-150400.5.12.3 * libpcp_gui2-6.2.0-150400.5.12.3 * pcp-devel-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.12.3 * libpcp_mmv1-debuginfo-6.2.0-150400.5.12.3 * libpcp-devel-6.2.0-150400.5.12.3 * pcp-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-6.2.0-150400.5.12.3 * pcp-6.2.0-150400.5.12.3 * libpcp_gui2-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-6.2.0-150400.5.12.3 * python3-pcp-6.2.0-150400.5.12.3 * pcp-system-tools-debuginfo-6.2.0-150400.5.12.3 * python3-pcp-debuginfo-6.2.0-150400.5.12.3 * libpcp_trace2-6.2.0-150400.5.12.3 * libpcp_web1-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogSummary-6.2.0-150400.5.12.3 * libpcp_web1-6.2.0-150400.5.12.3 * perl-PCP-MMV-6.2.0-150400.5.12.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * pcp-import-mrtg2pcp-6.2.0-150400.5.12.3 * pcp-import-sar2pcp-6.2.0-150400.5.12.3 * pcp-conf-6.2.0-150400.5.12.3 * pcp-import-iostat2pcp-6.2.0-150400.5.12.3 * pcp-doc-6.2.0-150400.5.12.3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * pcp-system-tools-6.2.0-150400.5.12.3 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.12.3 * pcp-devel-6.2.0-150400.5.12.3 *libpcp_mmv1-6.2.0-150400.5.12.3 * libpcp_trace2-debuginfo-6.2.0-150400.5.12.3 * pcp-debugsource-6.2.0-150400.5.12.3 * libpcp3-6.2.0-150400.5.12.3 * perl-PCP-PMDA-6.2.0-150400.5.12.3 * libpcp3-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-debuginfo-6.2.0-150400.5.12.3 * libpcp_gui2-6.2.0-150400.5.12.3 * pcp-devel-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.12.3 * libpcp_mmv1-debuginfo-6.2.0-150400.5.12.3 * libpcp-devel-6.2.0-150400.5.12.3 * pcp-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-6.2.0-150400.5.12.3 * pcp-6.2.0-150400.5.12.3 * libpcp_gui2-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-6.2.0-150400.5.12.3 * python3-pcp-6.2.0-150400.5.12.3 * pcp-system-tools-debuginfo-6.2.0-150400.5.12.3 * python3-pcp-debuginfo-6.2.0-150400.5.12.3 * libpcp_trace2-6.2.0-150400.5.12.3 * libpcp_web1-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogSummary-6.2.0-150400.5.12.3 * libpcp_web1-6.2.0-150400.5.12.3 * perl-PCP-MMV-6.2.0-150400.5.12.3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * pcp-import-mrtg2pcp-6.2.0-150400.5.12.3 * pcp-import-sar2pcp-6.2.0-150400.5.12.3 * pcp-conf-6.2.0-150400.5.12.3 * pcp-import-iostat2pcp-6.2.0-150400.5.12.3 * pcp-doc-6.2.0-150400.5.12.3 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * pcp-system-tools-6.2.0-150400.5.12.3 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.12.3 * pcp-devel-6.2.0-150400.5.12.3 * libpcp_mmv1-6.2.0-150400.5.12.3 * libpcp_trace2-debuginfo-6.2.0-150400.5.12.3 * pcp-debugsource-6.2.0-150400.5.12.3 * libpcp3-6.2.0-150400.5.12.3 * perl-PCP-PMDA-6.2.0-150400.5.12.3 * libpcp3-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-debuginfo-6.2.0-150400.5.12.3 * libpcp_gui2-6.2.0-150400.5.12.3 * pcp-devel-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.12.3 * libpcp_mmv1-debuginfo-6.2.0-150400.5.12.3 * libpcp-devel-6.2.0-150400.5.12.3 * pcp-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-6.2.0-150400.5.12.3 * pcp-6.2.0-150400.5.12.3 * libpcp_gui2-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-6.2.0-150400.5.12.3 * python3-pcp-6.2.0-150400.5.12.3 * pcp-system-tools-debuginfo-6.2.0-150400.5.12.3 * python3-pcp-debuginfo-6.2.0-150400.5.12.3 * libpcp_trace2-6.2.0-150400.5.12.3 * libpcp_web1-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogSummary-6.2.0-150400.5.12.3 * libpcp_web1-6.2.0-150400.5.12.3 * perl-PCP-MMV-6.2.0-150400.5.12.3 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * pcp-import-mrtg2pcp-6.2.0-150400.5.12.3 * pcp-import-sar2pcp-6.2.0-150400.5.12.3 * pcp-conf-6.2.0-150400.5.12.3 * pcp-import-iostat2pcp-6.2.0-150400.5.12.3 * pcp-doc-6.2.0-150400.5.12.3 * SUSE Linux Enterprise Server 15 SP4 LTSS (ppc64le) * pcp-pmda-perfevent-6.2.0-150400.5.12.3 * pcp-pmda-perfevent-debuginfo-6.2.0-150400.5.12.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * pcp-system-tools-6.2.0-150400.5.12.3 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.12.3 * pcp-devel-6.2.0-150400.5.12.3 * libpcp_mmv1-6.2.0-150400.5.12.3 * libpcp_trace2-debuginfo-6.2.0-150400.5.12.3 * pcp-debugsource-6.2.0-150400.5.12.3 * libpcp3-6.2.0-150400.5.12.3 * perl-PCP-PMDA-6.2.0-150400.5.12.3 * libpcp3-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-debuginfo-6.2.0-150400.5.12.3 * libpcp_gui2-6.2.0-150400.5.12.3 * pcp-devel-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.12.3 * libpcp_mmv1-debuginfo-6.2.0-150400.5.12.3 * libpcp-devel-6.2.0-150400.5.12.3 * pcp-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-6.2.0-150400.5.12.3 * pcp-6.2.0-150400.5.12.3 * libpcp_gui2-debuginfo-6.2.0-150400.5.12.3 *perl-PCP-MMV-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-6.2.0-150400.5.12.3 * python3-pcp-6.2.0-150400.5.12.3 * pcp-system-tools-debuginfo-6.2.0-150400.5.12.3 * python3-pcp-debuginfo-6.2.0-150400.5.12.3 * libpcp_trace2-6.2.0-150400.5.12.3 * libpcp_web1-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogSummary-6.2.0-150400.5.12.3 * libpcp_web1-6.2.0-150400.5.12.3 * perl-PCP-MMV-6.2.0-150400.5.12.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * pcp-import-mrtg2pcp-6.2.0-150400.5.12.3 * pcp-import-sar2pcp-6.2.0-150400.5.12.3 * pcp-conf-6.2.0-150400.5.12.3 * pcp-import-iostat2pcp-6.2.0-150400.5.12.3 * pcp-doc-6.2.0-150400.5.12.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le) * pcp-pmda-perfevent-6.2.0-150400.5.12.3 * pcp-pmda-perfevent-debuginfo-6.2.0-150400.5.12.3 ## References: * https://www.suse.com/security/cve/CVE-2023-6917.html * https://bugzilla.suse.com/show_bug.cgi?id=1217826 * https://bugzilla.suse.com/show_bug.cgi?id=1222815 . A new release for pcp tackles a vulnerability within SUSE offerings, enhancing overall stability and operational efficiency. Vital updates have been integrated.. pcp update, SUSE security, performance improvement, system stability, threat mitigation. . LinuxSecurity.com Team
An update that solves one vulnerability and has one security fix can now be installed.. # Security update for pcp Announcement ID: SUSE-SU-2025:0801-1 Release Date: 2025-03-06T14:04:47Z Rating: moderate References: * bsc#1217826 * bsc#1222815 Cross-References: * CVE-2023-6917 CVSS scores: * CVE-2023-6917 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for pcp fixes the following issues: * Version upgrade 6.2.0 (bsc#1217826, PED#8192, CVE-2023-6917). * Performance CoPilot 6 is not starting due to missing pmlogger_daily.timer (bsc#1222815). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-801=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-801=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-801=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-801=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-801=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * perl-PCP-LogSummary-6.2.0-150400.5.12.3 *pcp-system-tools-6.2.0-150400.5.12.3 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.12.3 * pcp-devel-6.2.0-150400.5.12.3 * pcp-pmda-logger-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-cifs-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-sendmail-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-hacluster-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-shping-debuginfo-6.2.0-150400.5.12.3 * libpcp_mmv1-6.2.0-150400.5.12.3 * libpcp_trace2-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-cifs-6.2.0-150400.5.12.3 * pcp-pmda-cisco-debuginfo-6.2.0-150400.5.12.3 * pcp-gui-6.2.0-150400.5.12.3 * pcp-pmda-hacluster-6.2.0-150400.5.12.3 * pcp-pmda-mailq-debuginfo-6.2.0-150400.5.12.3 * pcp-debugsource-6.2.0-150400.5.12.3 * libpcp3-6.2.0-150400.5.12.3 * pcp-pmda-mounts-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-apache-6.2.0-150400.5.12.3 * pcp-pmda-summary-6.2.0-150400.5.12.3 * pcp-pmda-weblog-6.2.0-150400.5.12.3 * perl-PCP-PMDA-6.2.0-150400.5.12.3 * libpcp3-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-zimbra-6.2.0-150400.5.12.3 * libpcp_gui2-6.2.0-150400.5.12.3 * pcp-devel-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-systemd-6.2.0-150400.5.12.3 * pcp-pmda-weblog-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.12.3 * libpcp_mmv1-debuginfo-6.2.0-150400.5.12.3 * libpcp-devel-6.2.0-150400.5.12.3 * pcp-import-collectl2pcp-6.2.0-150400.5.12.3 * pcp-pmda-summary-debuginfo-6.2.0-150400.5.12.3 * pcp-testsuite-debuginfo-6.2.0-150400.5.12.3 * pcp-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-mailq-6.2.0-150400.5.12.3 * pcp-pmda-gfs2-6.2.0-150400.5.12.3 * pcp-pmda-systemd-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-gfs2-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-shping-6.2.0-150400.5.12.3 * pcp-6.2.0-150400.5.12.3 * perl-PCP-LogImport-6.2.0-150400.5.12.3 * libpcp_gui2-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-bash-6.2.0-150400.5.12.3 *perl-PCP-MMV-6.2.0-150400.5.12.3 * pcp-pmda-smart-6.2.0-150400.5.12.3 * pcp-pmda-dm-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-sendmail-6.2.0-150400.5.12.3 * pcp-gui-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-bind2-6.2.0-150400.5.12.3 * pcp-pmda-dm-6.2.0-150400.5.12.3 * pcp-pmda-smart-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-bash-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-6.2.0-150400.5.12.3 * pcp-pmda-nvidia-gpu-debuginfo-6.2.0-150400.5.12.3 * python3-pcp-6.2.0-150400.5.12.3 * pcp-pmda-lustrecomm-debuginfo-6.2.0-150400.5.12.3 * pcp-system-tools-debuginfo-6.2.0-150400.5.12.3 * python3-pcp-debuginfo-6.2.0-150400.5.12.3 * pcp-testsuite-6.2.0-150400.5.12.3 * pcp-import-collectl2pcp-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-apache-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-roomtemp-6.2.0-150400.5.12.3 * pcp-pmda-sockets-6.2.0-150400.5.12.3 * libpcp_trace2-6.2.0-150400.5.12.3 * pcp-pmda-logger-6.2.0-150400.5.12.3 * pcp-pmda-lustrecomm-6.2.0-150400.5.12.3 * libpcp_web1-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-trace-6.2.0-150400.5.12.3 * pcp-pmda-sockets-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-cisco-6.2.0-150400.5.12.3 * pcp-pmda-mounts-6.2.0-150400.5.12.3 * pcp-pmda-roomtemp-debuginfo-6.2.0-150400.5.12.3 * libpcp_web1-6.2.0-150400.5.12.3 * pcp-pmda-trace-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-nvidia-gpu-6.2.0-150400.5.12.3 * pcp-pmda-zimbra-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-docker-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-docker-6.2.0-150400.5.12.3 * openSUSE Leap 15.4 (noarch) * pcp-pmda-json-6.2.0-150400.5.12.3 * pcp-export-pcp2spark-6.2.0-150400.5.12.3 * pcp-conf-6.2.0-150400.5.12.3 * pcp-export-pcp2elasticsearch-6.2.0-150400.5.12.3 * pcp-pmda-haproxy-6.2.0-150400.5.12.3 * pcp-export-pcp2zabbix-6.2.0-150400.5.12.3 * pcp-export-pcp2graphite-6.2.0-150400.5.12.3 *pcp-pmda-slurm-6.2.0-150400.5.12.3 * pcp-pmda-netcheck-6.2.0-150400.5.12.3 * pcp-pmda-lmsensors-6.2.0-150400.5.12.3 * pcp-pmda-lustre-6.2.0-150400.5.12.3 * pcp-pmda-rabbitmq-6.2.0-150400.5.12.3 * pcp-pmda-memcache-6.2.0-150400.5.12.3 * pcp-pmda-oracle-6.2.0-150400.5.12.3 * pcp-pmda-ds389log-6.2.0-150400.5.12.3 * pcp-pmda-openmetrics-6.2.0-150400.5.12.3 * pcp-pmda-gpfs-6.2.0-150400.5.12.3 * pcp-export-pcp2influxdb-6.2.0-150400.5.12.3 * pcp-pmda-bonding-6.2.0-150400.5.12.3 * pcp-import-ganglia2pcp-6.2.0-150400.5.12.3 * pcp-pmda-mysql-6.2.0-150400.5.12.3 * pcp-pmda-ds389-6.2.0-150400.5.12.3 * pcp-pmda-unbound-6.2.0-150400.5.12.3 * pcp-export-pcp2xml-6.2.0-150400.5.12.3 * pcp-pmda-news-6.2.0-150400.5.12.3 * pcp-pmda-zswap-6.2.0-150400.5.12.3 * pcp-pmda-samba-6.2.0-150400.5.12.3 * pcp-pmda-rsyslog-6.2.0-150400.5.12.3 * pcp-import-mrtg2pcp-6.2.0-150400.5.12.3 * pcp-pmda-postfix-6.2.0-150400.5.12.3 * pcp-pmda-snmp-6.2.0-150400.5.12.3 * pcp-pmda-named-6.2.0-150400.5.12.3 * pcp-pmda-activemq-6.2.0-150400.5.12.3 * pcp-pmda-nutcracker-6.2.0-150400.5.12.3 * pcp-doc-6.2.0-150400.5.12.3 * pcp-pmda-nfsclient-6.2.0-150400.5.12.3 * pcp-pmda-openvswitch-6.2.0-150400.5.12.3 * pcp-import-sar2pcp-6.2.0-150400.5.12.3 * pcp-pmda-gpsd-6.2.0-150400.5.12.3 * pcp-pmda-netfilter-6.2.0-150400.5.12.3 * pcp-pmda-pdns-6.2.0-150400.5.12.3 * pcp-pmda-mic-6.2.0-150400.5.12.3 * pcp-zeroconf-6.2.0-150400.5.12.3 * pcp-pmda-dbping-6.2.0-150400.5.12.3 * pcp-import-iostat2pcp-6.2.0-150400.5.12.3 * pcp-pmda-gluster-6.2.0-150400.5.12.3 * pcp-pmda-redis-6.2.0-150400.5.12.3 * pcp-pmda-nginx-6.2.0-150400.5.12.3 * pcp-pmda-elasticsearch-6.2.0-150400.5.12.3 * pcp-export-pcp2json-6.2.0-150400.5.12.3 * openSUSE Leap 15.4 (aarch64 ppc64le x86_64 i586) * pcp-pmda-infiniband-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-perfevent-6.2.0-150400.5.12.3 *pcp-pmda-perfevent-debuginfo-6.2.0-150400.5.12.3 * pcp-pmda-infiniband-6.2.0-150400.5.12.3 * openSUSE Leap 15.4 (x86_64) * pcp-pmda-resctrl-6.2.0-150400.5.12.3 * pcp-pmda-resctrl-debuginfo-6.2.0-150400.5.12.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * pcp-system-tools-6.2.0-150400.5.12.3 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.12.3 * pcp-devel-6.2.0-150400.5.12.3 * libpcp_mmv1-6.2.0-150400.5.12.3 * libpcp_trace2-debuginfo-6.2.0-150400.5.12.3 * pcp-debugsource-6.2.0-150400.5.12.3 * libpcp3-6.2.0-150400.5.12.3 * perl-PCP-PMDA-6.2.0-150400.5.12.3 * libpcp3-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-debuginfo-6.2.0-150400.5.12.3 * libpcp_gui2-6.2.0-150400.5.12.3 * pcp-devel-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.12.3 * libpcp_mmv1-debuginfo-6.2.0-150400.5.12.3 * libpcp-devel-6.2.0-150400.5.12.3 * pcp-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-6.2.0-150400.5.12.3 * pcp-6.2.0-150400.5.12.3 * libpcp_gui2-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-6.2.0-150400.5.12.3 * python3-pcp-6.2.0-150400.5.12.3 * pcp-system-tools-debuginfo-6.2.0-150400.5.12.3 * python3-pcp-debuginfo-6.2.0-150400.5.12.3 * libpcp_trace2-6.2.0-150400.5.12.3 * libpcp_web1-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogSummary-6.2.0-150400.5.12.3 * libpcp_web1-6.2.0-150400.5.12.3 * perl-PCP-MMV-6.2.0-150400.5.12.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * pcp-import-mrtg2pcp-6.2.0-150400.5.12.3 * pcp-import-sar2pcp-6.2.0-150400.5.12.3 * pcp-conf-6.2.0-150400.5.12.3 * pcp-import-iostat2pcp-6.2.0-150400.5.12.3 * pcp-doc-6.2.0-150400.5.12.3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * pcp-system-tools-6.2.0-150400.5.12.3 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.12.3 *pcp-devel-6.2.0-150400.5.12.3 * libpcp_mmv1-6.2.0-150400.5.12.3 * libpcp_trace2-debuginfo-6.2.0-150400.5.12.3 * pcp-debugsource-6.2.0-150400.5.12.3 * libpcp3-6.2.0-150400.5.12.3 * perl-PCP-PMDA-6.2.0-150400.5.12.3 * libpcp3-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-debuginfo-6.2.0-150400.5.12.3 * libpcp_gui2-6.2.0-150400.5.12.3 * pcp-devel-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.12.3 * libpcp_mmv1-debuginfo-6.2.0-150400.5.12.3 * libpcp-devel-6.2.0-150400.5.12.3 * pcp-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-6.2.0-150400.5.12.3 * pcp-6.2.0-150400.5.12.3 * libpcp_gui2-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-6.2.0-150400.5.12.3 * python3-pcp-6.2.0-150400.5.12.3 * pcp-system-tools-debuginfo-6.2.0-150400.5.12.3 * python3-pcp-debuginfo-6.2.0-150400.5.12.3 * libpcp_trace2-6.2.0-150400.5.12.3 * libpcp_web1-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogSummary-6.2.0-150400.5.12.3 * libpcp_web1-6.2.0-150400.5.12.3 * perl-PCP-MMV-6.2.0-150400.5.12.3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * pcp-import-mrtg2pcp-6.2.0-150400.5.12.3 * pcp-import-sar2pcp-6.2.0-150400.5.12.3 * pcp-conf-6.2.0-150400.5.12.3 * pcp-import-iostat2pcp-6.2.0-150400.5.12.3 * pcp-doc-6.2.0-150400.5.12.3 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * pcp-system-tools-6.2.0-150400.5.12.3 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.12.3 * pcp-devel-6.2.0-150400.5.12.3 * libpcp_mmv1-6.2.0-150400.5.12.3 * libpcp_trace2-debuginfo-6.2.0-150400.5.12.3 * pcp-debugsource-6.2.0-150400.5.12.3 * libpcp3-6.2.0-150400.5.12.3 * perl-PCP-PMDA-6.2.0-150400.5.12.3 * libpcp3-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-debuginfo-6.2.0-150400.5.12.3 * libpcp_gui2-6.2.0-150400.5.12.3 * pcp-devel-debuginfo-6.2.0-150400.5.12.3 *perl-PCP-LogImport-debuginfo-6.2.0-150400.5.12.3 * libpcp_mmv1-debuginfo-6.2.0-150400.5.12.3 * libpcp-devel-6.2.0-150400.5.12.3 * pcp-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-6.2.0-150400.5.12.3 * pcp-6.2.0-150400.5.12.3 * libpcp_gui2-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-6.2.0-150400.5.12.3 * python3-pcp-6.2.0-150400.5.12.3 * pcp-system-tools-debuginfo-6.2.0-150400.5.12.3 * python3-pcp-debuginfo-6.2.0-150400.5.12.3 * libpcp_trace2-6.2.0-150400.5.12.3 * libpcp_web1-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogSummary-6.2.0-150400.5.12.3 * libpcp_web1-6.2.0-150400.5.12.3 * perl-PCP-MMV-6.2.0-150400.5.12.3 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * pcp-import-mrtg2pcp-6.2.0-150400.5.12.3 * pcp-import-sar2pcp-6.2.0-150400.5.12.3 * pcp-conf-6.2.0-150400.5.12.3 * pcp-import-iostat2pcp-6.2.0-150400.5.12.3 * pcp-doc-6.2.0-150400.5.12.3 * SUSE Linux Enterprise Server 15 SP4 LTSS (ppc64le) * pcp-pmda-perfevent-6.2.0-150400.5.12.3 * pcp-pmda-perfevent-debuginfo-6.2.0-150400.5.12.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * pcp-system-tools-6.2.0-150400.5.12.3 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.12.3 * pcp-devel-6.2.0-150400.5.12.3 * libpcp_mmv1-6.2.0-150400.5.12.3 * libpcp_trace2-debuginfo-6.2.0-150400.5.12.3 * pcp-debugsource-6.2.0-150400.5.12.3 * libpcp3-6.2.0-150400.5.12.3 * perl-PCP-PMDA-6.2.0-150400.5.12.3 * libpcp3-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-debuginfo-6.2.0-150400.5.12.3 * libpcp_gui2-6.2.0-150400.5.12.3 * pcp-devel-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.12.3 * libpcp_mmv1-debuginfo-6.2.0-150400.5.12.3 * libpcp-devel-6.2.0-150400.5.12.3 * pcp-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogImport-6.2.0-150400.5.12.3 * pcp-6.2.0-150400.5.12.3 *libpcp_gui2-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.12.3 * libpcp_import1-6.2.0-150400.5.12.3 * python3-pcp-6.2.0-150400.5.12.3 * pcp-system-tools-debuginfo-6.2.0-150400.5.12.3 * python3-pcp-debuginfo-6.2.0-150400.5.12.3 * libpcp_trace2-6.2.0-150400.5.12.3 * libpcp_web1-debuginfo-6.2.0-150400.5.12.3 * perl-PCP-LogSummary-6.2.0-150400.5.12.3 * libpcp_web1-6.2.0-150400.5.12.3 * perl-PCP-MMV-6.2.0-150400.5.12.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * pcp-import-mrtg2pcp-6.2.0-150400.5.12.3 * pcp-import-sar2pcp-6.2.0-150400.5.12.3 * pcp-conf-6.2.0-150400.5.12.3 * pcp-import-iostat2pcp-6.2.0-150400.5.12.3 * pcp-doc-6.2.0-150400.5.12.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le) * pcp-pmda-perfevent-6.2.0-150400.5.12.3 * pcp-pmda-perfevent-debuginfo-6.2.0-150400.5.12.3 ## References: * https://www.suse.com/security/cve/CVE-2023-6917.html * https://bugzilla.suse.com/show_bug.cgi?id=1217826 * https://bugzilla.suse.com/show_bug.cgi?id=1222815 . SUSE releases a targeted security patch for pcp that resolves CVE-2023-6917, complete with detailed update guidelines.. openSUSE update, pcp patch, SUSE security, performance CoPilot, advisory update. . LinuxSecurity.com Team
An update that solves three vulnerabilities and has two security fixes can now be installed.. # Security update for pcp Announcement ID: SUSE-SU-2025:0011-1 Release Date: 2025-01-03T16:49:10Z Rating: moderate References: * bsc#1217826 * bsc#1222815 * bsc#1230551 * bsc#1230552 * bsc#1231345 Cross-References: * CVE-2023-6917 * CVE-2024-45769 * CVE-2024-45770 CVSS scores: * CVE-2023-6917 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2024-45769 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-45769 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45769 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-45770 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2024-45770 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2024-45770 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.4 An update that solves three vulnerabilities and has two security fixes can now be installed. ## Description: This update for pcp fixes the following issues: Upgrade to 6.2.0 (bsc#1217826 / PED#8192): * CVE-2024-45770: Fixed symlink race (bsc#1230552). * CVE-2024-45769: Fixed pmstore corruption (bsc#1230551) * CVE-2023-6917: Fixed local privilege escalation from pcp user to root (bsc#1217826). Bug fixes: * Reintroduce libuv support for SLE > = 15 (bsc#1231345). * move pmlogger_daily into main package (bsc#1222815) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-11=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * pcp-pmda-summary-6.2.0-150400.5.9.1 * pcp-pmda-summary-debuginfo-6.2.0-150400.5.9.1 *libpcp_mmv1-6.2.0-150400.5.9.1 * libpcp3-debuginfo-6.2.0-150400.5.9.1 * libpcp_web1-debuginfo-6.2.0-150400.5.9.1 * pcp-devel-6.2.0-150400.5.9.1 * pcp-pmda-cifs-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-sockets-debuginfo-6.2.0-150400.5.9.1 * libpcp_trace2-6.2.0-150400.5.9.1 * pcp-devel-debuginfo-6.2.0-150400.5.9.1 * pcp-import-collectl2pcp-6.2.0-150400.5.9.1 * pcp-pmda-bind2-6.2.0-150400.5.9.1 * pcp-pmda-smart-6.2.0-150400.5.9.1 * pcp-testsuite-debuginfo-6.2.0-150400.5.9.1 * libpcp_web1-6.2.0-150400.5.9.1 * pcp-pmda-docker-6.2.0-150400.5.9.1 * pcp-pmda-cifs-6.2.0-150400.5.9.1 * pcp-testsuite-6.2.0-150400.5.9.1 * pcp-pmda-nvidia-gpu-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-zimbra-debuginfo-6.2.0-150400.5.9.1 * pcp-system-tools-6.2.0-150400.5.9.1 * pcp-pmda-shping-6.2.0-150400.5.9.1 * pcp-6.2.0-150400.5.9.1 * libpcp-devel-6.2.0-150400.5.9.1 * pcp-pmda-hacluster-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-lustrecomm-6.2.0-150400.5.9.1 * pcp-pmda-logger-debuginfo-6.2.0-150400.5.9.1 * libpcp_gui2-debuginfo-6.2.0-150400.5.9.1 * libpcp_import1-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-zimbra-6.2.0-150400.5.9.1 * pcp-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-apache-6.2.0-150400.5.9.1 * pcp-pmda-bash-6.2.0-150400.5.9.1 * pcp-pmda-mailq-6.2.0-150400.5.9.1 * libpcp_gui2-6.2.0-150400.5.9.1 * pcp-debugsource-6.2.0-150400.5.9.1 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.9.1 * pcp-system-tools-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-trace-6.2.0-150400.5.9.1 * pcp-pmda-sendmail-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-apache-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-gfs2-6.2.0-150400.5.9.1 * pcp-pmda-mounts-6.2.0-150400.5.9.1 * pcp-pmda-cisco-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-mounts-debuginfo-6.2.0-150400.5.9.1 * perl-PCP-MMV-6.2.0-150400.5.9.1 * pcp-pmda-weblog-debuginfo-6.2.0-150400.5.9.1 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.9.1 *pcp-pmda-dm-6.2.0-150400.5.9.1 * libpcp_mmv1-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-hacluster-6.2.0-150400.5.9.1 * pcp-pmda-roomtemp-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-weblog-6.2.0-150400.5.9.1 * libpcp_trace2-debuginfo-6.2.0-150400.5.9.1 * libpcp3-6.2.0-150400.5.9.1 * pcp-pmda-systemd-6.2.0-150400.5.9.1 * perl-PCP-LogImport-6.2.0-150400.5.9.1 * python3-pcp-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-sendmail-6.2.0-150400.5.9.1 * pcp-pmda-docker-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-dm-debuginfo-6.2.0-150400.5.9.1 * perl-PCP-PMDA-6.2.0-150400.5.9.1 * pcp-pmda-roomtemp-6.2.0-150400.5.9.1 * python3-pcp-6.2.0-150400.5.9.1 * pcp-gui-debuginfo-6.2.0-150400.5.9.1 * pcp-import-collectl2pcp-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-lustrecomm-debuginfo-6.2.0-150400.5.9.1 * pcp-gui-6.2.0-150400.5.9.1 * pcp-pmda-smart-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-trace-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-shping-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-sockets-6.2.0-150400.5.9.1 * perl-PCP-LogSummary-6.2.0-150400.5.9.1 * libpcp_import1-6.2.0-150400.5.9.1 * pcp-pmda-systemd-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-cisco-6.2.0-150400.5.9.1 * pcp-pmda-bash-debuginfo-6.2.0-150400.5.9.1 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-mailq-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-nvidia-gpu-6.2.0-150400.5.9.1 * pcp-pmda-logger-6.2.0-150400.5.9.1 * pcp-pmda-gfs2-debuginfo-6.2.0-150400.5.9.1 * openSUSE Leap 15.4 (noarch) * pcp-pmda-gluster-6.2.0-150400.5.9.1 * pcp-doc-6.2.0-150400.5.9.1 * pcp-pmda-ds389log-6.2.0-150400.5.9.1 * pcp-pmda-elasticsearch-6.2.0-150400.5.9.1 * pcp-pmda-openvswitch-6.2.0-150400.5.9.1 * pcp-pmda-nutcracker-6.2.0-150400.5.9.1 * pcp-pmda-ds389-6.2.0-150400.5.9.1 * pcp-pmda-unbound-6.2.0-150400.5.9.1 * pcp-import-iostat2pcp-6.2.0-150400.5.9.1 * pcp-pmda-postfix-6.2.0-150400.5.9.1 * pcp-pmda-bonding-6.2.0-150400.5.9.1 *pcp-pmda-lustre-6.2.0-150400.5.9.1 * pcp-pmda-news-6.2.0-150400.5.9.1 * pcp-pmda-samba-6.2.0-150400.5.9.1 * pcp-import-sar2pcp-6.2.0-150400.5.9.1 * pcp-pmda-json-6.2.0-150400.5.9.1 * pcp-pmda-mysql-6.2.0-150400.5.9.1 * pcp-pmda-netcheck-6.2.0-150400.5.9.1 * pcp-export-pcp2zabbix-6.2.0-150400.5.9.1 * pcp-pmda-memcache-6.2.0-150400.5.9.1 * pcp-pmda-zswap-6.2.0-150400.5.9.1 * pcp-pmda-oracle-6.2.0-150400.5.9.1 * pcp-import-ganglia2pcp-6.2.0-150400.5.9.1 * pcp-pmda-rsyslog-6.2.0-150400.5.9.1 * pcp-zeroconf-6.2.0-150400.5.9.1 * pcp-pmda-lmsensors-6.2.0-150400.5.9.1 * pcp-pmda-activemq-6.2.0-150400.5.9.1 * pcp-pmda-netfilter-6.2.0-150400.5.9.1 * pcp-export-pcp2elasticsearch-6.2.0-150400.5.9.1 * pcp-import-mrtg2pcp-6.2.0-150400.5.9.1 * pcp-pmda-mic-6.2.0-150400.5.9.1 * pcp-pmda-slurm-6.2.0-150400.5.9.1 * pcp-export-pcp2json-6.2.0-150400.5.9.1 * pcp-export-pcp2graphite-6.2.0-150400.5.9.1 * pcp-pmda-named-6.2.0-150400.5.9.1 * pcp-pmda-gpfs-6.2.0-150400.5.9.1 * pcp-pmda-haproxy-6.2.0-150400.5.9.1 * pcp-export-pcp2influxdb-6.2.0-150400.5.9.1 * pcp-conf-6.2.0-150400.5.9.1 * pcp-pmda-nginx-6.2.0-150400.5.9.1 * pcp-pmda-openmetrics-6.2.0-150400.5.9.1 * pcp-pmda-dbping-6.2.0-150400.5.9.1 * pcp-pmda-pdns-6.2.0-150400.5.9.1 * pcp-pmda-redis-6.2.0-150400.5.9.1 * pcp-pmda-snmp-6.2.0-150400.5.9.1 * pcp-pmda-gpsd-6.2.0-150400.5.9.1 * pcp-pmda-nfsclient-6.2.0-150400.5.9.1 * pcp-export-pcp2spark-6.2.0-150400.5.9.1 * pcp-export-pcp2xml-6.2.0-150400.5.9.1 * pcp-pmda-rabbitmq-6.2.0-150400.5.9.1 * openSUSE Leap 15.4 (aarch64 ppc64le x86_64 i586) * pcp-pmda-perfevent-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-infiniband-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-infiniband-6.2.0-150400.5.9.1 * pcp-pmda-perfevent-6.2.0-150400.5.9.1 * openSUSE Leap 15.4 (x86_64) * pcp-pmda-resctrl-debuginfo-6.2.0-150400.5.9.1 * pcp-pmda-resctrl-6.2.0-150400.5.9.1 ## References: *https://www.suse.com/security/cve/CVE-2023-6917.html * https://www.suse.com/security/cve/CVE-2024-45769.html * https://www.suse.com/security/cve/CVE-2024-45770.html * https://bugzilla.suse.com/show_bug.cgi?id=1217826 * https://bugzilla.suse.com/show_bug.cgi?id=1222815 * https://bugzilla.suse.com/show_bug.cgi?id=1230551 * https://bugzilla.suse.com/show_bug.cgi?id=1230552 * https://bugzilla.suse.com/show_bug.cgi?id=1231345 . A revision for openSUSE addresses several significant security flaws in pcp, including potential local privilege escalation and data integrity issues.. openSUSE, pcp security fix, security update 2025, Linux update, local privilege escalation. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.