PT-2026-66402 · Pcp+1 · Pcp+1

CVE-2026-16529

·

Published

2026-07-30

·

Updated

2026-08-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PCP (affected versions not specified)
Description A signed integer overflow occurs in the pmGetPDU() function during PDU processing or SASL negotiation. An attacker can exploit this by sending crafted network packets, which permanently blinds the affected daemon and leads to a total denial of service (DoS) for subsequent packet reads.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:55560
ALSA-2026:55617
ALSA-2026:55740
AZL-94374
CVE-2026-16529
OPENSUSE-SU-2026:11490-1
OPENSUSE-SU-2026:21636-1
SUSE-SU-2026:23064-1
SUSE-SU-2026:23174-1
SUSE-SU-2026:23277-1
SUSE-SU-2026:23316-1
SUSE-SU-2026:3505-1
SUSE-SU-2026:3506-1
SUSE-SU-2026:3507-1
SUSE-SU-2026:3508-1

Affected Products

Pcp
Rocky Linux