{"id":"AZL-82425","summary":"CVE-2026-4878 affecting package libcap for versions less than 2.69-14","details":"A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.","modified":"2026-08-31T05:26:27Z","published":"2026-04-09T16:16:31Z","upstream":["CVE-2026-4878"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-4878"}],"affected":[{"package":{"name":"libcap","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/libcap"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.69-14"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-82425.json"}}],"schema_version":"1.9.0"}