CVE-2026-45254: Incorrect libcap_net limitation list manipulation
In the case of the cap_net service, when a key present in the old limit was omitted from the new limit, the missing key was treated as "allow any" instead of being rejected. In certain scenarios, an application that had previously restricted a subset of network operations could ask for a new limit that extended the permissions of the process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45254?
The severity of CVE-2026-45254 is medium with a score of 6.5.
How do I fix CVE-2026-45254?
To fix CVE-2026-45254, ensure that libcap_net is updated to the latest version that addresses the incorrect limitation list manipulation.
What types of systems are affected by CVE-2026-45254?
CVE-2026-45254 affects systems running FreeBSD and the libcap library specifically for network capabilities.
What is the impact of CVE-2026-45254?
The impact of CVE-2026-45254 allows applications to potentially bypass network operation restrictions due to incorrect handling of limit keys.
Is CVE-2026-45254 a permanent vulnerability?
No, CVE-2026-45254 can be mitigated by updating to patched versions of the affected software.