Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-19130

Опубликовано: 16 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-19130: libcap security update (IMPORTANT)

[2.69-7.1]

  • Fix TOCTOU race condition in cap_set_file() (CVE-2026-4878) Resolves: RHEL-169302

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

libcap

2.69-7.el10_2.1

libcap-devel

2.69-7.el10_2.1

Oracle Linux x86_64

libcap

2.69-7.el10_2.1

libcap-devel

2.69-7.el10_2.1

Связанные CVE

Связанные уязвимости

CVSS3: 6.7
ubuntu
4 месяца назад

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.

CVSS3: 6.7
redhat
4 месяца назад

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.

CVSS3: 6.7
nvd
4 месяца назад

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.

CVSS3: 6.7
msrc
4 месяца назад

Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()

CVSS3: 6.7
debian
4 месяца назад

A flaw was found in libcap. A local unprivileged user can exploit a Ti ...