PCP linux_sockets Module Exposes Unsecured Connection for Privilege Escalation
CVE-2026-16526 Published on July 30, 2026
Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability
A flaw in the PCP linux_sockets module exposes an unsecured internal connection.
An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
Vulnerability Analysis
CVE-2026-16526 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Timeline
Reported to Red Hat.
Made public. 8 days later.
Weakness Type
What is a File descriptor leak Vulnerability?
A process does not close sensitive file descriptors before invoking a child process, which allows the child to perform unauthorized I/O operations using those descriptors. When a new process is forked or executed, the child process inherits any open file descriptors. When the child process has fewer privileges than the parent process, this might introduce a vulnerability if the child process can access the file descriptor but does not have the privileges to access the associated file.
CVE-2026-16526 has been classified to as a File descriptor leak vulnerability or weakness.
Products Associated with CVE-2026-16526
stack.watch emails you whenever new vulnerabilities are published in Red Hat Enterprise Linux (RHEL) or Red Hat Openshift. Just hit a watch button to start following.