Debian Package Tracker
Register | Log in
Subscribe

pcp

System level performance monitoring and performance management

Choose email to subscribe with

general
  • source: pcp (main)
  • version: 7.2.2-1
  • maintainer: PCP Development Team (DMD)
  • uploaders: Nathan Scott [DMD] – Ken McDonell [DMD]
  • arch: all any
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 5.2.6-1
  • oldstable: 6.0.3-1.1
  • stable: 6.3.8-1
  • unstable: 7.2.2-1
versioned links
  • 5.2.6-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.0.3-1.1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 6.3.8-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 7.2.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 7.2.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libpcp-archive1
  • libpcp-archive1-dev
  • libpcp-gui2
  • libpcp-gui2-dev
  • libpcp-import-perl
  • libpcp-import1
  • libpcp-import1-dev
  • libpcp-import2
  • libpcp-import2-dev
  • libpcp-logsummary-perl
  • libpcp-mmv-perl
  • libpcp-mmv1
  • libpcp-mmv1-dev
  • libpcp-pmda-perl
  • libpcp-pmda3
  • libpcp-pmda3-dev
  • libpcp-trace2
  • libpcp-trace2-dev
  • libpcp-web1
  • libpcp-web1-dev
  • libpcp3
  • libpcp3-dev
  • libpcp4
  • libpcp4-dev
  • pcp (2 bugs: 0, 2, 0, 0)
  • pcp-atop
  • pcp-conf
  • pcp-doc
  • pcp-dstat (1 bugs: 0, 1, 0, 0)
  • pcp-export-pcp2elasticsearch
  • pcp-export-pcp2graphite
  • pcp-export-pcp2influxdb
  • pcp-export-pcp2json
  • pcp-export-pcp2spark
  • pcp-export-pcp2xlsx
  • pcp-export-pcp2xml
  • pcp-export-pcp2zabbix
  • pcp-export-zabbix-agent
  • pcp-gui
  • pcp-htop
  • pcp-import-benchmarks
  • pcp-import-collectl2pcp
  • pcp-import-ganglia2pcp
  • pcp-import-guidellm2pcp
  • pcp-import-iostat2pcp
  • pcp-import-mrtg2pcp
  • pcp-import-sar2pcp
  • pcp-import-sheet2pcp
  • pcp-pmda-infiniband
  • pcp-testsuite
  • pcp-zeroconf
  • python3-pcp
action needed
lintian reports 2 errors and 11 warnings high
Lintian reports 2 errors and 11 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-08-14 Last update: 2026-10-07 15:01
10 security issues in bookworm high

There are 10 open security issues in bookworm.

6 important issues:
  • CVE-2026-16524: A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
  • CVE-2026-16526: A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
  • CVE-2026-16527: An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
  • CVE-2026-16529: A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.
  • CVE-2026-16530: A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.
  • CVE-2026-16531: An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.
4 issues postponed or untriaged:
  • CVE-2023-6917: (needs triaging) A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in privilege levels poses a risk when privileged root processes interact with directories or directory trees owned by unprivileged PCP users. Specifically, this vulnerability may lead to the compromise of PCP user isolation and facilitate local PCP-to-root exploits, particularly through symlink attacks. These vulnerabilities underscore the importance of maintaining robust privilege separation mechanisms within PCP to mitigate the potential for unauthorized privilege escalation.
  • CVE-2024-3019: (needs triaging) A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.
  • CVE-2024-45769: (needs triaging) A vulnerability was found in Performance Co-Pilot (PCP).  This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash.
  • CVE-2024-45770: (needs triaging) A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which is used to log messages in the system. Under certain conditions, it runs with high-level privileges.
Created: 2024-02-29 Last update: 2026-10-07 11:30
9 security issues in bullseye high

There are 9 open security issues in bullseye.

6 important issues:
  • CVE-2026-16524: A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
  • CVE-2026-16526: A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
  • CVE-2026-16527: An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
  • CVE-2026-16529: A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.
  • CVE-2026-16530: A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.
  • CVE-2026-16531: An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.
2 issues postponed or untriaged:
  • CVE-2023-6917: (needs triaging) A vulnerability has been identified in the Performance Co-Pilot (PCP) package, stemming from the mixed privilege levels utilized by systemd services associated with PCP. While certain services operate within the confines of limited PCP user/group privileges, others are granted full root privileges. This disparity in privilege levels poses a risk when privileged root processes interact with directories or directory trees owned by unprivileged PCP users. Specifically, this vulnerability may lead to the compromise of PCP user isolation and facilitate local PCP-to-root exploits, particularly through symlink attacks. These vulnerabilities underscore the importance of maintaining robust privilege separation mechanisms within PCP to mitigate the potential for unauthorized privilege escalation.
  • CVE-2024-3019: (needs triaging) A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to the local network, allowing remote command execution with the privileges of the Redis user. This issue can only be exploited when pmproxy is running. By default, pmproxy is not running and needs to be started manually. The pmproxy service is usually started from the 'Metrics settings' page of the Cockpit web interface. This flaw affects PCP versions 4.3.4 and newer.
1 ignored issue:
  • CVE-2024-45770: A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which is used to log messages in the system. Under certain conditions, it runs with high-level privileges.
Created: 2026-07-30 Last update: 2026-08-29 19:00
AppStream hints: 1 error and 1 warning for pcp-gui high
AppStream found metadata issues for packages:
  • pcp-gui: 1 error and 1 warning
You should get rid of them to provide more metadata about this software.
Created: 2018-06-04 Last update: 2026-02-23 04:00
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 7.2.3-1, distribution unstable) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit 0d181a1ea7de33a77ef20d8ad339e968c78e13b6
Author: Nathan Scott <nathans@redhat.com>
Date:   Wed Oct 7 15:32:24 2026 +1100

    build: add gitignore file for pmimprot lib on macos

commit caa2da898c7d530a1485e6a77a8003e82f1da49a
Author: Nathan Scott <nathans@redhat.com>
Date:   Wed Oct 7 15:32:04 2026 +1100

    docs: update version number and next planned release date

commit 725a6e7ff4b9461f3ea6da265d1e1370d9d102fb
Merge: 87fc51f5 79708000
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Oct 7 14:59:18 2026 +1100

    Merge pull request #2761 from kmcdonell/nextrel
    
    QA updates held over from last release

commit 797080009a6069114a3be7e878e2e28776e5cca0
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Oct 7 14:57:07 2026 +1100

    src/libpcp_web/install-dev: better error handling control and exit status

commit 55a510e08d18a6aed2f4cf64db406d597da3b333
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Oct 7 14:55:22 2026 +1100

    src/pmdas/bpftrace/examples: keep raw files from github
    
    So we can isolate problems as (a) from github or (b) from our local
    rewriting.
    
        modified: src/pmdas/bpftrace/examples/Download
        new file: src/pmdas/bpftrace/examples/biolatency-v27.bt.raw
        new file: src/pmdas/bpftrace/examples/runqlat-v27.bt.raw

commit b1905348834c00eec35dc0b97b85086808743f34
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Oct 7 13:42:01 2026 +1100

    install-dev: update scripts for *BSD where make is not gmake
    
        modified:   src/libpcp/src/install-dev
        modified:   src/libpcp_web/install-dev

commit 6e0283ea7e23e1edb152bcad41ffb0e3b5c2e30a
Merge: 8b632443 6525a5c9
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Oct 7 13:37:40 2026 +1100

    Merge branch 'main' into nextrel

commit 6525a5c91ef9e5288e6165b25fde7ae5819677df
Merge: dc4077fc 87fc51f5
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Oct 7 13:32:49 2026 +1100

    Merge branch 'main' of https://github.com/performancecopilot/pcp

commit 8b632443fb63363f09708f719ae7643b994d05ce
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Oct 7 06:56:44 2026 +1100

    src/pmsearch/.gitignore: add a couple of build by-products

commit 59367a2d1deb1ca76ffe9db5733553540fad8f4e
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Oct 7 06:55:30 2026 +1100

    qa/group: add 1211 to sanity group
    
    Provides pmseries coverage in CI via -g sanity QA run.

commit 2f53a1d0357f60381294254663bbd4522119bacb
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Oct 7 06:55:00 2026 +1100

    qa/1742: tweak filter

commit 5938df6c8f007c9bc312a4897f984aef3650f77d
Merge: c2a2b701 dc4077fc
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Oct 7 06:54:14 2026 +1100

    Merge branch 'main' into nextrel

commit dc4077fcce7a411cfd89b6187aeee7272f652e46
Merge: 9a6a70a2 aa1ce942
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Wed Oct 7 06:53:06 2026 +1100

    Merge branch 'main' of https://github.com/performancecopilot/pcp

commit c2a2b701a7dbc9a451e1694ae44dec2dd34dc748
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Oct 6 07:55:31 2026 +1100

    bpftrace PMDA: add examples for v27 of bpftrace
    
    Seen on Debian unstable.
    
    Also correct typo in qa/1721 for message to warn about newer version
    of bpftrace.

commit 9a6a70a25bfd3d59267b180e1e09a9b346300d71
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Oct 6 07:36:51 2026 +1100

    qa/1334: tweak hostname(1) usage
    
    pmhostname works better (and hostname -f does not work everywhere).

commit 086e60c1016738dedaefde8721611c4e739b0a8d
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Oct 6 07:24:20 2026 +1100

    src/libpcp_web/install-dev: small improvements
    
    - use install-dev in each dir if it exists ... ensures
      multiarch install for libpcp_web updates the "right" DSOs
    - pmsearch is not built on all platforms

commit 568901e78f00ecef9309d1edfefe401eb199cd3e
Author: Ken McDonell <kenj@kenj.id.au>
Date:   Tue Oct 6 06:30:21 2026 +1100

    Revert "libpcp_web: fix follow-up Coverity use-after-free issues"
    
    This reverts commit 8dccebd1adffaf5af67e61c6fbcc4cab2b292206.
Created: 2026-05-23 Last update: 2026-10-07 09:19
Multiarch hinter reports 1 issue(s) low
There are issues with the multiarch metadata for this package.
  • pcp-doc could be marked Multi-Arch: foreign
Created: 2016-09-14 Last update: 2026-10-07 18:30
6 low-priority security issues in trixie low

There are 6 open security issues in trixie.

6 issues left for the package maintainer to handle:
  • CVE-2026-16524: (needs triaging) A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.filter metric. This failed validation lets attackers execute arbitrary commands as the PMDA user when metrics refresh.
  • CVE-2026-16526: (needs triaging) A flaw in the PCP linux_sockets module exposes an unsecured internal connection. An attacker with initial code execution can exploit this to escalate privileges and execute arbitrary commands as root.
  • CVE-2026-16527: (needs triaging) An unauthenticated remote attacker can bypass access controls by sending crafted requests to the PCP pmproxy /store endpoint. This allows the attacker to overwrite any PMDA metric, leading to arbitrary code execution and system takeover.
  • CVE-2026-16529: (needs triaging) A signed integer overflow in the PCP __pmGetPDU() function can be exploited via crafted network packets during PDU processing or SASL negotiation. This permanently blinds the affected daemon, resulting in a total denial of service (DoS) for subsequent packet reads.
  • CVE-2026-16530: (needs triaging) A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in the `pmLogLoadInDom()` function by sending a specially crafted request. This bypasses a critical bounds check, which can lead to the `pmproxy` service crashing, causing a Denial of Service (DoS). Additionally, this flaw may enable the leakage of sensitive information from the system's memory.
  • CVE-2026-16531: (needs triaging) An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a crafted hostname. This allows arbitrary file and directory creation, potentially leading to a denial of service.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-07-30 Last update: 2026-10-07 11:30
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.2).
Created: 2025-12-23 Last update: 2026-10-07 09:20
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
  • excuses:
    • Migration status for pcp (- to 7.2.2-1): BLOCKED: Rejected/violates migration policy/introduces a regression
    • Issues preventing migration:
    • ∙ ∙ New but not reproduced on amd64 - info: pcp-testsuite
    • ∙ ∙ New but not reproduced on arm64 - info: pcp, pcp-testsuite
    • ∙ ∙ New but not reproduced on armhf - info: pcp, pcp-testsuite
    • ∙ ∙ New but not reproduced on i386 - info: pcp, pcp-testsuite
    • ∙ ∙ Missing build on riscv64
    • ∙ ∙ Autopkgtest deferred on riscv64: missing arch:riscv64 build
    • ∙ ∙ Lintian check waiting for test results on riscv64 - info
    • ∙ ∙ Too young, only 1 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/p/pcp.html
    • Not considered
news
[rss feed]
  • [2026-10-07] Accepted pcp 7.2.2-1 (source) into unstable (Nathan Scott)
  • [2026-08-30] pcp REMOVED from testing (Debian testing watch)
  • [2026-08-16] pcp 7.2.1-2 MIGRATED to testing (Debian testing watch)
  • [2026-08-14] Accepted pcp 7.2.1-2 (source) into unstable (Nathan Scott)
  • [2026-08-01] pcp 7.2.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-30] Accepted pcp 7.2.0-1 (source arm64 all) into unstable (Debian FTP Masters) (signed by: Nathan Scott)
  • [2026-05-29] pcp 7.1.5-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-26] Accepted pcp 7.1.5-1 (source) into unstable (Nathan Scott)
  • [2026-05-25] pcp 7.1.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-22] Accepted pcp 7.1.4-1 (source) into unstable (Nathan Scott)
  • [2026-05-02] Accepted pcp 7.1.3-2 (source) into unstable (Nathan Scott)
  • [2026-04-27] pcp 7.1.2-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-24] Accepted pcp 7.1.2-1 (source) into unstable (Nathan Scott)
  • [2026-04-02] pcp 7.1.1-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-30] Accepted pcp 7.1.1-1 (source) into unstable (Nathan Scott)
  • [2026-01-30] pcp 7.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-28] Accepted pcp 7.1.0-1 (source) into unstable (Nathan Scott)
  • [2025-12-05] pcp 7.0.5-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-21] Accepted pcp 7.0.5-1 (source) into unstable (Nathan Scott)
  • [2025-11-19] Accepted pcp 7.0.4-1 (source) into unstable (Nathan Scott)
  • [2025-11-12] Accepted pcp 7.0.3-1 (source arm64 all) into unstable (Nathan Scott)
  • [2025-11-01] pcp REMOVED from testing (Debian testing watch)
  • [2025-10-16] Accepted pcp 7.0.2-1 (source arm64 all) into unstable (Debian FTP Masters) (signed by: Nathan Scott)
  • [2025-09-23] Accepted pcp 7.0.1-1 (source arm64 all) into unstable (Debian FTP Masters) (signed by: Nathan Scott)
  • [2025-09-01] Accepted pcp 7.0.0-1 (source arm64 all) into unstable (Debian FTP Masters) (signed by: Nathan Scott)
  • [2025-04-21] pcp 6.3.8-1 MIGRATED to testing (Debian testing watch)
  • [2025-04-11] Accepted pcp 6.3.8-1 (source) into unstable (Nathan Scott)
  • [2025-04-07] pcp 6.3.7-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-28] Accepted pcp 6.3.7-1 (source) into unstable (Nathan Scott)
  • [2025-03-17] Accepted pcp 6.3.6-1 (source) into unstable (Nathan Scott)
  • 1
  • 2
bugs [bug history graph]
  • all: 3
  • RC: 0
  • I&N: 3
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (2, 11)
  • buildd: logs, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 7.2.1-2build1
  • 2 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing