Race Condition Vulnerability in libcap Affects Red Hat Products
CVE-2026-4878
6.7MEDIUM
What is CVE-2026-4878?
A flaw in libcap exposes a race condition within the cap_set_file() function, enabling an unprivileged local user with write access to a parent directory to exploit this vulnerability. By redirecting file capability updates to an attacker-controlled file, an attacker can inject or strip capabilities from executables. This manipulation can lead to unauthorized privilege escalation, risking system integrity and security.
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Ali Raza for reporting this issue.