{"id":"UBUNTU-CVE-2026-4878","details":"A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.","modified":"2026-06-24T02:29:23.557692146Z","published":"2026-04-09T16:16:00Z","related":["USN-8193-1","USN-8193-2"],"upstream":["CVE-2026-4878"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-4878"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-4878"},{"type":"REPORT","url":"https://sites.google.com/site/fullycapable/release-notes-for-libcap#h.x4zn8j3lss6r"},{"type":"REPORT","url":"https://github.com/AndrewGMorgan/libcap_mirror/security/advisories/GHSA-f78v-p5hx-m7hh"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8193-1"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8193-2"}],"affected":[{"package":{"name":"libcap2","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/libcap2?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.24-0ubuntu2+esm2"}]}],"versions":["1:2.22-1.2ubuntu2","1:2.24-0ubuntu1","1:2.24-0ubuntu2","1:2.24-0ubuntu2+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"libcap2","binary_version":"1:2.24-0ubuntu2+esm2"},{"binary_version":"1:2.24-0ubuntu2+esm2","binary_name":"libcap2-bin"},{"binary_name":"libpam-cap","binary_version":"1:2.24-0ubuntu2+esm2"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4878.json"}},{"package":{"name":"libcap2","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/libcap2?arch=source&distro=esm-infra-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.24-12ubuntu0.1~esm2"}]}],"versions":["1:2.24-9","1:2.24-12","1:2.24-12ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"1:2.24-12ubuntu0.1~esm2","binary_name":"libcap2"},{"binary_name":"libcap2-bin","binary_version":"1:2.24-12ubuntu0.1~esm2"},{"binary_version":"1:2.24-12ubuntu0.1~esm2","binary_name":"libpam-cap"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4878.json"}},{"package":{"name":"libcap2","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/libcap2?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.25-1.2ubuntu0.1~esm2"}]}],"versions":["1:2.25-1.1","1:2.25-1.2","1:2.25-1.2ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"1:2.25-1.2ubuntu0.1~esm2","binary_name":"libcap2"},{"binary_version":"1:2.25-1.2ubuntu0.1~esm2","binary_name":"libcap2-bin"},{"binary_name":"libpam-cap","binary_version":"1:2.25-1.2ubuntu0.1~esm2"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4878.json"}},{"package":{"name":"libcap2","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/libcap2?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.32-1ubuntu0.2+esm1"}]}],"versions":["1:2.25-2","1:2.27-1","1:2.32-1","1:2.32-1ubuntu0.1","1:2.32-1ubuntu0.2"],"ecosystem_specific":{"binaries":[{"binary_name":"libcap2","binary_version":"1:2.32-1ubuntu0.2+esm1"},{"binary_name":"libcap2-bin","binary_version":"1:2.32-1ubuntu0.2+esm1"},{"binary_version":"1:2.32-1ubuntu0.2+esm1","binary_name":"libpam-cap"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4878.json"}},{"package":{"name":"libcap2","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/libcap2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.44-1ubuntu0.22.04.3"}]}],"versions":["1:2.44-1build1","1:2.44-1build2","1:2.44-1build3","1:2.44-1ubuntu0.22.04.1","1:2.44-1ubuntu0.22.04.2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libcap2","binary_version":"1:2.44-1ubuntu0.22.04.3"},{"binary_version":"1:2.44-1ubuntu0.22.04.3","binary_name":"libcap2-bin"},{"binary_version":"1:2.44-1ubuntu0.22.04.3","binary_name":"libpam-cap"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4878.json"}},{"package":{"name":"libcap2","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/libcap2?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.66-5ubuntu2.4"}]}],"versions":["1:2.66-4ubuntu1","1:2.66-5ubuntu1","1:2.66-5ubuntu2","1:2.66-5ubuntu2.1","1:2.66-5ubuntu2.2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"1:2.66-5ubuntu2.4","binary_name":"libcap2"},{"binary_version":"1:2.66-5ubuntu2.4","binary_name":"libcap2-bin"},{"binary_name":"libpam-cap","binary_version":"1:2.66-5ubuntu2.4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4878.json"}},{"package":{"name":"libcap2","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/libcap2?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:2.75-7ubuntu2.2"}]}],"versions":["1:2.73-4ubuntu1","1:2.75-7ubuntu1","1:2.75-7ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"golang-kernel-pub-linux-libs-security-libcap-dev","binary_version":"1:2.75-7ubuntu2.2"},{"binary_version":"1:2.75-7ubuntu2.2","binary_name":"libcap2"},{"binary_name":"libcap2-bin","binary_version":"1:2.75-7ubuntu2.2"},{"binary_name":"libpam-cap","binary_version":"1:2.75-7ubuntu2.2"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-4878.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]}