Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-4878

Опубликовано: 09 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 6.7

Описание

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the cap_set_file() function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.

РелизСтатусПримечание
devel

not-affected

1:2.75-10ubuntu2
esm-infra-legacy/trusty

released

1:2.24-0ubuntu2+esm2
esm-infra-legacy/xenial

released

1:2.24-12ubuntu0.1~esm2
esm-infra/bionic

released

1:2.25-1.2ubuntu0.1~esm2
esm-infra/focal

released

1:2.32-1ubuntu0.2+esm1
esm-infra/xenial

ignored

end of ESM support, was needs-triage
jammy

released

1:2.44-1ubuntu0.22.04.3
noble

released

1:2.66-5ubuntu2.4
questing

released

1:2.75-7ubuntu2.2
resolute

not-affected

1:2.75-10ubuntu2

Показывать по

EPSS

Процентиль: 11%
0.00206
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
redhat
4 месяца назад

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.

CVSS3: 6.7
nvd
4 месяца назад

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.

CVSS3: 6.7
msrc
4 месяца назад

Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()

CVSS3: 6.7
debian
4 месяца назад

A flaw was found in libcap. A local unprivileged user can exploit a Ti ...

suse-cvrf
3 месяца назад

Security update for libcap

EPSS

Процентиль: 11%
0.00206
Низкий

6.7 Medium

CVSS3