CVE-2023-6917
Alma Linux vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2023-6917) has been identified in the Performance Co-Pilot (PCP) package, discovered by Matthias Gerstner from the SUSE Linux security team. The vulnerability stems from mixed privilege levels in systemd services associated with PCP, where some services operate with limited PCP user/group privileges while others have full root privileges. This vulnerability was disclosed on February 28, 2024, and affects PCP implementations in various Linux distributions (Red Hat CVE, NVD).

Technical details

The vulnerability arises from the interaction between privileged root processes and directories owned by unprivileged PCP users. Specifically, shared directory structures such as '/var/lib/pcp/tmp' and '/var/log/pcp' (both owned by pcp:pcp with mode 775) are accessed by services running with different privilege levels. The CVSS v3.1 base score is 6.0 (Moderate), with the vector string CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N (Red Hat CVE).

Impact

The vulnerability can lead to the compromise of PCP user isolation and facilitate local PCP-to-root privilege escalation exploits. The severity is classified as moderate rather than important due to mitigating factors, including the requirement of an already compromised pcp system account and specific conditions such as the existence of symbolic links and the ability to manipulate directory structures (Red Hat CVE).

Exploitability

Exploitation requires local access and an already compromised pcp system account. The vulnerability can be exploited through symlink attacks when privileged root processes interact with directories or directory trees controlled by unprivileged users (Red Hat Bugzilla).

Mitigation and workarounds

Red Hat has addressed this vulnerability in Red Hat Enterprise Linux 9 through the security advisory RHSA-2024:2213, which provides an update to PCP version 6.2.0-1. Currently, no specific workarounds are available that meet Red Hat Product Security criteria for ease of use and deployment (Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related Alma Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84639CRITICAL9.1
  • NixOS logoNixOS
  • thunderbird
NoYesSep 01, 2026
CVE-2026-14957HIGH7.5
  • Rocky Linux logoRocky Linux
  • openshift::ose-rhel-coreos-9-0:4.20.9.6.202609021029-0
NoYesSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • thunderbird
NoYesSep 01, 2026
CVE-2026-84640HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management