Database/Control plane, storage & DevOps
Performance Co-Pilot: signed integer overflow in __pmGetPDU permanently blinds the collector daemon
Impact
A crafted PDU sent during normal PDU processing or SASL negotiation drives a signed integer overflow in __pmGetPDU(), after which the affected daemon never reads another packet correctly - it is permanently blinded until restarted. On a GPU fleet PCP is frequently the metrics collector of record for node health, thermals and per-job resource accounting, and it is the backend behind Red Hat's performance tooling on RHEL and OpenShift nodes. Losing it does not stop GPU workloads, but it silently removes the telemetry an operator uses to notice a wedged node, a throttling GPU, or a job that has stopped making progress. Unauthenticated and remote, so any host that can reach pmcd's port can take collection down and keep it down.
Who can reach it
Anyone with network reach to a PCP daemon's listening port - no authentication required; the overflow can be triggered before or during SASL negotiation.
What to do
Update the pcp packages from the Red Hat errata (RHSA-2026:55560, RHSA-2026:55617, RHSA-2026:55740) and restart pmcd and any other affected PCP daemons; a wedged daemon also needs a restart to recover, workloads on the node are not disturbed. Until patched, restrict pmcd to the management network with a firewall rule rather than leaving it reachable from tenant networks.
References
Related entries
- Automated Logic WebCTRL / i-Vu server and controllers, BACnet transport trust: This is the vendor formally concedingCVE-2026-32666 · Automated Logic WebCTRL / i-Vu server and controllers, BACnet transport trustHigh
- Apache Tomcat: Missing encryption of sensitive data introduced by the CVE-2026-29146 fixCVE-2026-34486 · Apache TomcatHigh
- JFrog Artifactory: internal anonymous-user token returned to unauthenticated callersCVE-2026-42018 · JFrog Artifactory (anonymous-user token disclosure)High
- Prometheus: Azure AD remote-write client secret served in plaintext from the /-/config endpointCVE-2026-42151 · Prometheus (Azure AD remote-write OAuth client_secret in /-/config)High
- Prometheus: unvalidated snappy decoded length on /api/v1/read lets a small request exhaust server memoryCVE-2026-42154 · Prometheus (/api/v1/read snappy decompression length handling)High
- OpenTelemetry JS Prometheus exporter: a malformed request URI crashes the whole Node.js processCVE-2026-44902 · OpenTelemetry JS Prometheus exporter (@opentelemetry/exporter-prometheus, also via sdk-node)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.