Description
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.
Published: 2026-04-09
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

A flaw in libcap’s cap_set_file() implementation creates a time‑of‑check-to-time‑of‑use race condition. A local, unprivileged user who can write in the parent directory of a capability file can redirect capability updates to an attacker‑controlled file, thereby injecting or stripping capabilities from executables and obtaining elevated privileges. This vulnerability is a classic race condition, identified as CWE‑367.

Affected Systems

Red Hat Enterprise Linux versions 6 through 10, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4 are listed as affected. Any system running the vulnerable version of libcap within these products is vulnerable; the user does not need initial elevated rights beyond write access to the relevant directory.

Risk and Exploitability

The CVSS score is 6.7, indicating moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires local access and the ability to write in a directory that contains capability files; no publicly known exploits exist yet. Since no official workaround is available, the risk persists until the patch is applied. Users should monitor for updates and consider restricting file‑level write permissions as a temporary measure.

Generated by OpenCVE AI on April 9, 2026 at 19:23 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply the most recent patched version of libcap from Red Hat’s official repositories as soon as it becomes available.
  • Limit write permissions on directories that contain capability files so that only privileged users can modify them.
  • Monitor the Red Hat security advisory page and apply new updates promptly.
  • No official workaround is provided; applying the vendor patch is currently the only remediation.

Generated by OpenCVE AI on April 9, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8193-2 libcap vulnerability
References
Link Providers
http://www.openwall.com/lists/oss-security/2026/04/07/14 cve-icon
http://www.openwall.com/lists/oss-security/2026/04/07/4 cve-icon
http://www.openwall.com/lists/oss-security/2026/04/08/9 cve-icon
http://www.openwall.com/lists/oss-security/2026/04/09/5 cve-icon
http://www.openwall.com/lists/oss-security/2026/04/09/6 cve-icon
https://access.redhat.com/errata/RHSA-2026:12423 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:12441 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:13285 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:14162 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:14937 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:19130 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:19346 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:19456 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:19458 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:20595 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:21254 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:21275 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:22634 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:22957 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:23233 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:23245 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:24346 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:25044 cve-icon
https://access.redhat.com/errata/RHSA-2026:25096 cve-icon cve-icon
https://access.redhat.com/errata/RHSA-2026:25181 cve-icon
https://access.redhat.com/errata/RHSA-2026:26542 cve-icon
https://access.redhat.com/errata/RHSA-2026:27998 cve-icon
https://access.redhat.com/errata/RHSA-2026:29197 cve-icon
https://access.redhat.com/errata/RHSA-2026:30078 cve-icon
https://access.redhat.com/errata/RHSA-2026:30087 cve-icon
https://access.redhat.com/errata/RHSA-2026:30088 cve-icon
https://access.redhat.com/errata/RHSA-2026:30089 cve-icon
https://access.redhat.com/errata/RHSA-2026:7473 cve-icon cve-icon
https://access.redhat.com/security/cve/CVE-2026-4878 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2447554 cve-icon cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2451615 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2026-4878 cve-icon
https://www.cve.org/CVERecord?id=CVE-2026-4878 cve-icon
History

Sat, 27 Jun 2026 08:15:00 +0000


Thu, 25 Jun 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:ai_inference_server:3.3::el9
References

Thu, 25 Jun 2026 11:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.13::el9
References

Wed, 24 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
References

Mon, 22 Jun 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat cost Management
CPEs cpe:/a:redhat:cost_management:4::el9
Vendors & Products Redhat cost Management
References

Thu, 18 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.16::el9
References

Thu, 18 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.18::el9
References

Thu, 11 Jun 2026 10:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4.15::el9
References

Wed, 10 Jun 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ai Inference Server
CPEs cpe:/a:redhat:ai_inference_server:3.2::el9
Vendors & Products Redhat ai Inference Server
References

Wed, 10 Jun 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:openshift:4 cpe:/a:redhat:openshift:4.19::el9
References

Mon, 08 Jun 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Aus
Redhat rhel Eus Long Life
CPEs cpe:/o:redhat:rhel_aus:8.6::baseos
cpe:/o:redhat:rhel_eus_long_life:8.6::baseos
Vendors & Products Redhat rhel Aus
Redhat rhel Eus Long Life
References

Thu, 04 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Tus
CPEs cpe:/o:redhat:rhel_e4s:8.8::baseos
cpe:/o:redhat:rhel_tus:8.8::baseos
Vendors & Products Redhat rhel Tus
References

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat insights Proxy
CPEs cpe:/a:redhat:insights_proxy:1.5::el9
Vendors & Products Redhat insights Proxy
References

Wed, 27 May 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel E4s
CPEs cpe:/a:redhat:rhel_e4s:9.2::appstream
cpe:/o:redhat:rhel_e4s:9.2::baseos
Vendors & Products Redhat rhel E4s
References

Wed, 27 May 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhui
CPEs cpe:/a:redhat:rhui:5::el9
Vendors & Products Redhat rhui
References

Tue, 26 May 2026 09:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:rhel_eus:9.4::appstream
cpe:/o:redhat:rhel_eus:9.4::baseos
References

Wed, 20 May 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat rhel Eus
CPEs cpe:/a:redhat:rhel_eus:9.6::appstream
cpe:/o:redhat:rhel_eus:9.6::baseos
Vendors & Products Redhat rhel Eus
References

Wed, 20 May 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat enterprise Linux Eus
CPEs cpe:/o:redhat:enterprise_linux_eus:10.0
Vendors & Products Redhat enterprise Linux Eus
References

Tue, 19 May 2026 22:45:00 +0000

Type Values Removed Values Added
References

Tue, 19 May 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:10.2
References

Thu, 07 May 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat discovery
CPEs cpe:/a:redhat:discovery:2::el9
Vendors & Products Redhat discovery
References

Wed, 06 May 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Distributed Tracing
CPEs cpe:/a:redhat:openshift_distributed_tracing:3.9::el9
Vendors & Products Redhat openshift Distributed Tracing
References

Mon, 04 May 2026 02:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:8::baseos
References

Thu, 30 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:9 cpe:/a:redhat:enterprise_linux:9::appstream
cpe:/o:redhat:enterprise_linux:9::baseos
References

Thu, 30 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:10.1
References

Tue, 28 Apr 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Libcap Project
Libcap Project libcap
CPEs cpe:2.3:a:libcap_project:libcap:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products Libcap Project
Libcap Project libcap

Sat, 25 Apr 2026 01:45:00 +0000

Type Values Removed Values Added
References

Fri, 10 Apr 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat hardened Images
Redhat openshift Container Platform
Vendors & Products Redhat hardened Images
Redhat openshift Container Platform

Fri, 10 Apr 2026 04:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Apr 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 09 Apr 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat hummingbird
CPEs cpe:/a:redhat:hummingbird:1
Vendors & Products Redhat hummingbird

Thu, 09 Apr 2026 16:30:00 +0000


Thu, 09 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.
Title Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()
First Time appeared Redhat
Redhat enterprise Linux
Redhat openshift
Weaknesses CWE-367
CPEs cpe:/a:redhat:openshift:4
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat openshift
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Libcap Project Libcap
Redhat Ai Inference Server Cost Management Discovery Enterprise Linux Enterprise Linux Eus Hardened Images Hummingbird Insights Proxy Openshift Openshift Container Platform Openshift Distributed Tracing Rhel Aus Rhel E4s Rhel Eus Rhel Eus Long Life Rhel Tus Rhui
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-06-30T12:10:35.145Z

Reserved: 2026-03-26T06:32:41.308Z

Link: CVE-2026-4878

cve-icon Vulnrichment

Updated: 2026-04-09T15:36:22.355Z

cve-icon NVD

Status : Modified

Published: 2026-04-09T16:16:31.987

Modified: 2026-06-17T20:17:23.350

Link: CVE-2026-4878

cve-icon Redhat

Severity : Important

Publid Date: 2026-04-06T00:00:00Z

Links: CVE-2026-4878 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-10T09:32:33Z

Weaknesses
  • CWE-367

    Time-of-check Time-of-use (TOCTOU) Race Condition