CVE-2026-4878: Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()
Published Mar 26, 2026
·Updated
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.
Affected Software
9 affected componentsFixes available
libcap libcap
Microsoft cbl2 libcap 2.60-7
Microsoft azl3 libcap 2.69-13
Microsoft azl3 libcap 2.69-14
Libcap Project Libcap
redhat OpenShift Container Platform=4.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0
Event History
Mar 26, 2026
Data Sourced
via Red Hat·06:56 AM
DescriptionSeverityAffected Software
Apr 9, 2026
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Apr 11, 2026
Data Sourced
via Microsoft·08:10 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:10 AM
Affected Software
Updated
via Microsoft·08:10 AM
DescriptionSeverity
Aug 11, 58291
Event
via NVD·02:48 AM