A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94377.json"