System-level performance monitoring and performance management
Go to file
RHEL Packaging Agent 5d3ebc9889 Fix CVE-2026-16530: arbitrary pointer deref in __pmLogLoadInDom
Backport upstream fix for CVE-2026-16530, an arbitrary pointer
dereference in __pmLogLoadInDom (CWE-125/822). The combined
patch cherry-picks three upstream commits: the primary fix
adding bounds checks and validation in e_indom.c for both
libpcp and libpcp3, plus two regression fixes for
pmlogrewrite and pmlogextract callers. QA tests are also
updated to exercise the new failure modes.

CVE: CVE-2026-16530
Upstream patches:
 - ec81e2b35c.patch
 - b72da5135d.patch
 - edfd909eda.patch
Resolves: RHEL-213746

This commit was backported by Ymir, a Red Hat Enterprise Linux software maintenance AI agent.

Assisted-by: Ymir
2026-07-30 12:37:26 +00:00
.fmf Initial implementation of Fedora gating for PCP 2021-02-08 08:20:06 +01:00
.gitignore Update to latest community sources (PCP v6) 2022-08-31 15:36:47 +10:00
ci.fmf Fix of ci.fmf 2025-09-30 14:58:32 +02:00
gating.yaml Reconfigured gating 2025-09-24 08:59:03 +02:00
pcp-7.1.5-CVE-2026-16530.patch Fix CVE-2026-16530: arbitrary pointer deref in __pmLogLoadInDom 2026-07-30 12:37:26 +00:00
pcp.spec Fix CVE-2026-16530: arbitrary pointer deref in __pmLogLoadInDom 2026-07-30 12:37:26 +00:00
rpminspect.yaml Rebase to pcp-7.1.5 2026-06-08 09:49:59 -04:00
sources Rebase to pcp-7.1.5 2026-06-08 09:49:59 -04:00