Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94386.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94386
Upstream
  • CVE-2026-16530
Published
2026-07-30T06:25:03Z
Modified
2026-08-30T05:24:52Z
Summary
CVE-2026-16530 affecting package pcp 6.3.2-1
Details

A flaw was found in the PCP (Performance Co-Pilot) pmproxy service. A remote attacker can exploit a vulnerability in the pmLogLoadInDom() function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the pmproxy service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.

References

Affected packages

Azure Linux:3 / pcp

Package

Name
pcp
Purl
pkg:rpm/azure-linux/pcp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.3.2-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94386.json"