CVE Vulnerabilities

CVE-2026-4878

Time-of-check Time-of-use (TOCTOU) Race Condition

Published: Apr 09, 2026 | Modified: Jun 11, 2026
CVSS 3.x
7
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
6.7 IMPORTANT
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the cap_set_file() function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.

Weakness

The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check.

Affected Software

NameVendorStart VersionEnd Version
LibcapLibcap_project- (including)- (including)
Openshift_container_platformRedhat4.0 (including)4.0 (including)
Enterprise_linuxRedhat8.0 (including)8.0 (including)
Enterprise_linuxRedhat9.0 (including)9.0 (including)
Enterprise_linuxRedhat10.0 (including)10.0 (including)
Red Hat Enterprise Linux 10RedHatlibcap-0:2.69-7.el10_1.1*
Red Hat Enterprise Linux 10RedHatlibcap-0:2.69-7.el10_2.1*
Red Hat Enterprise Linux 10.0 Extended Update SupportRedHatlibcap-0:2.69-7.el10_0.1*
Red Hat Enterprise Linux 8RedHatlibcap-0:2.48-6.el8_10.1*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatlibcap-0:2.48-4.el8_6.1*
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnRedHatlibcap-0:2.48-4.el8_6.1*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatlibcap-0:2.48-5.el8_8.1*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatlibcap-0:2.48-5.el8_8.1*
Red Hat Enterprise Linux 9RedHatlibcap-0:2.48-10.el9_7.1*
Red Hat Enterprise Linux 9RedHatlibcap-0:2.48-10.el9_8.1*
Red Hat Enterprise Linux 9RedHatlibcap-0:2.48-10.el9_7.1*
Red Hat Enterprise Linux 9RedHatlibcap-0:2.48-10.el9_8.1*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatlibcap-0:2.48-9.el9_2.1*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatlibcap-0:2.48-9.el9_4.1*
Red Hat Enterprise Linux 9.6 Extended Update SupportRedHatlibcap-0:2.48-9.el9_6.1*
Red Hat OpenShift Container Platform 4.15RedHatrhcos-415.92.202606030318-0*
Red Hat OpenShift Container Platform 4.16RedHatrhcos-416.94.202606051757-0*
Red Hat OpenShift Container Platform 4.18RedHatrhcos-418.94.202606051320-0*
Red Hat OpenShift Container Platform 4.19RedHatrhcos-4.19.9.6.202606031700-0*
Red Hat AI Inference Server 3.2RedHatrhaiis/model-opt-cuda-rhel9:1780681984*
Red Hat Discovery 2RedHatdiscovery/discovery-server-rhel9:1778101579*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:1778156756*
Red Hat Hardened ImagesRedHatlibcap-main-2.78-1.1.hum1*
Red Hat Insights proxy 1.5RedHatinsights-proxy/insights-proxy-container-rhel9:1780420428*
Red Hat OpenShift distributed tracing 3.9.3RedHatrhosdt/opentelemetry-collector-rhel9:1778056267*
Red Hat OpenShift distributed tracing 3.9.3RedHatrhosdt/opentelemetry-rhel9-operator:1778056233*
Red Hat OpenShift distributed tracing 3.9.3RedHatrhosdt/opentelemetry-target-allocator-rhel9:1778056245*
Red Hat Update Infrastructure 5RedHatrhui5/cds-rhel9:1779798159*
Red Hat Update Infrastructure 5RedHatrhui5/haproxy-rhel9:1779798164*
Red Hat Update Infrastructure 5RedHatrhui5/installer-rhel9:1779798165*
Red Hat Update Infrastructure 5RedHatrhui5/rhua-rhel9:1779798222*
Libcap2Ubuntuesm-infra/xenial*
Libcap2Ubuntujammy*
Libcap2Ubuntunoble*
Libcap2Ubuntuquesting*
Libcap2Ubuntuupstream*

Potential Mitigations

References