Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:13285

Опубликовано: 06 мая 2026
Источник: rocky
Оценка: Important

Описание

Important: libcap security update

Libcap is a library for getting and setting POSIX.1e (formerly POSIX 6) draft 15 capabilities.

Security Fix(es):

  • libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() (CVE-2026-4878)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libcapaarch646.el8_10.1libcap-2.48-6.el8_10.1.aarch64.rpm
libcap-develaarch646.el8_10.1libcap-devel-2.48-6.el8_10.1.aarch64.rpm
libcapi6866.el8_10.1libcap-2.48-6.el8_10.1.i686.rpm
libcapx86_646.el8_10.1libcap-2.48-6.el8_10.1.x86_64.rpm
libcap-develi6866.el8_10.1libcap-devel-2.48-6.el8_10.1.i686.rpm
libcap-develx86_646.el8_10.1libcap-devel-2.48-6.el8_10.1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 6.7
ubuntu
4 месяца назад

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.

CVSS3: 6.7
redhat
4 месяца назад

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.

CVSS3: 6.7
nvd
4 месяца назад

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.

CVSS3: 6.7
msrc
4 месяца назад

Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()

CVSS3: 6.7
debian
4 месяца назад

A flaw was found in libcap. A local unprivileged user can exploit a Ti ...