A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libcap-develUpgrade libcap | May 3, 2026 | Apr 30, 2026 |
| Alpine Linux | — | Upgrade libcap | Apr 13, 2026 | Apr 9, 2026 |
| Debian | — | Upgrade libcap2 | May 17, 2026 | May 17, 2026 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jul 2, 2026 | Jul 1, 2026 |
| Oracle_linux | — | Upgrade libcapUpgrade libcap-devel | May 4, 2026 | Apr 6, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 10, 2026 | Apr 6, 2026 |
| Redhat_linux | — | Upgrade libcapUpgrade libcap-develUpgrade libcap-debugsourceNo solution existsUpgrade libcap-debuginfo | May 4, 2026 | Apr 6, 2026 |
| Rocky_linux | — | Upgrade libcapUpgrade libcap-develUpgrade libcap-debugsourceUpgrade libcap-debuginfo | May 5, 2026 | May 3, 2026 |
| Suse | — | Upgrade libcap2-32bitUpgrade libcap-develUpgrade libcap-progsUpgrade libcap2Upgrade libpsx2 | Apr 21, 2026 | Apr 17, 2026 |
| Ubuntu | — | Upgrade libcap-dev (Ubuntu Pro)Upgrade libpam-cap (Ubuntu Pro)Upgrade libcap2-binUpgrade libcap2-bin (Ubuntu Pro)Upgrade libcap2 (Ubuntu Pro)Upgrade libcap2 | Apr 23, 2026 | Apr 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub