Skip to content
Red HatCVE-2026-16524

Red Hat Enterprise Linux 6: command injection

High7.8CVE-2026-16524 · Published Jul 30, 2026 · updated Aug 21, 2026

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
ansible-collection-redhat-leapp: information disclosure
Medium6.2Jul 30
ansible-collection-redhat-leapp.: insecure permissions
Medium5.5Jul 30
Red Hat Samba: out-of-bounds read
Medium5.3Jul 30
Red Hat Enterprise Linux 10: improper authorization
High8.8Jul 30
Red Hat Samba: denial of service
Medium5.3Jul 30
Red Hat Cost Management Metrics Operator: server-side request forgery
High7.6Jul 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.