Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:12441: Important: libcap security update

A Time-of-Check Time-of-Use (TOCTOU) race condition in the `cap_set_file()` function of libcap (CVE-2026-4878, CVSS 6.7) can allow local privilege escalation. The vulnerability affects libcap_project libcap up to unspecified versions and Red Hat Enterprise Linux versions 8.0, 9.0, and 10.0. For RHEL 9, Red Hat has released a fixed version in libcap-2.48-10.el9_7.1.
Read Full Article →

Red Hat Product Errata RHSA-2026:12441 - Security Advisory Issued: 2026-04-30 Updated: 2026-04-30 RHSA-2026:12441 - Security Advisory Overview Updated Packages Synopsis Important: libcap security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libcap is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Libcap is a library for getting and setting POSIX.1e (formerly POSIX 6) draft 15 capabilities. Security Fix(es): libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() (CVE-2026-4878) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Fixes BZ - 2451615 - CVE-2026-4878 libcap: libcap: Privilege escalation via TOCTOU race condition in cap_set_file() CVEs CVE-2026-4878 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM libcap-2.48-10.el9_7.1.src.rpm SHA-256: cd7b587671c0160d85802c044be0dc5a61366db815656a2a4210067a2d2c7303 x86_64 libcap-2.48-10.el9_7.1.i686.rpm SHA-256: 96bbe0e05739e619d5e6e10b8f2bdb4385c980249d4a6b2b1f33aef5a19cd7b5 libcap-2.48-10.el9_7.1.x86_64.rpm SHA-256: 47a89779b20db77b425aa7cafc4c9af3912d197e2abd07ab74cf540cc123357d libcap-debuginfo-2.48-10.el9_7.1.i686.rpm SHA-256: ebc9336886017a8f52c0d884f967380646d1e20bf2848237559d83dcb930607e libcap-debuginfo-2.48-10.el9_7.1.i686.rpm SHA-256: ebc9336886017a8f52c0d884f967380646d1e20bf2848237559d83dcb930607e libcap-debuginfo-2.48-10.el9_7.1.x86_64.rpm SHA-256: eaa7227e005f3ac81874b4ec37d3f26d58b76134d340aec0002bfb8aa607f3df libcap-debuginfo-2.48-10.el9_7.1.x86_64.rpm SHA-256: eaa7227e005f3ac81874b4ec37d3f26d58b76134d340aec0002bfb8aa607f3df libcap-debugsource-2.48-10.el9_7.1.i686.rpm SHA-256: fb5d21adc9d05e62e8fa84a6e32c0dc413ae462ad2632b697ab03c74d0779069 libcap-debugsource-2.48-10.el9_7.1.i686.rpm SHA-256: fb5d21adc9d05e62e8fa84a6e32c0dc413ae462ad2632b697ab03c74d0779069 libcap-debugsource-2.48-10.el9_7.1.x86_64.rpm SHA-256: 9c8c944bc1e0f810a177968b9eeeb044a4fa3f776baef6bf4d50aae6ea8748e1 libcap-debugsource-2.48-10.el9_7.1.x86_64.rpm SHA-256: 9c8c944bc1e0f810a177968b9eeeb044a4fa3f776baef6bf4d50aae6ea8748e1 libcap-devel-2.48-10.el9_7.1.i686.rpm SHA-256: 3db411c1abc284b546519c18bdcd5f713028738215a06c2dccc06e3ca27db6b6 libcap-devel-2.48-10.el9_7.1.x86_64.rpm SHA-256: 05de0f84c78232757d59f9bfb87051eea4ad84d193d8971f7a7d06c66b82e205 Red Hat Enterprise Linux for IBM z Systems 9 SRPM libcap-2.48-10.el9_7.1.src.rpm SHA-256: cd7b587671c0160d85802c044be0dc5a61366db815656a2a4210067a2d2c7303 s390x libcap-2.48-10.el9_7.1.s390x.rpm SHA-256: 78d75f7e2c991425bde05308d29f6f10e850010168a802e1fa59bb0b78fc3b6f libcap-debuginfo-2.48-10.el9_7.1.s390x.rpm SHA-256: 75d8549ee355cafdd29047cc33391f78b5f39c6b5a528d1e060fabda5b608405 libcap-debuginfo-2.48-10.el9_7.1.s390x.rpm SHA-256: 75d8549ee355cafdd29047cc33391f78b5f39c6b5a528d1e060fabda5b608405 libcap-debugsource-2.48-10.el9_7.1.s390x.rpm SHA-256: ca5f3f3a6a4aa4f0d5522e09f35f3ae6f6f4540a97bb0e612eeb5f404c4ca4fe libcap-debugsource-2.48-10.el9_7.1.s390x.rpm SHA-256: ca5f3f3a6a4aa4f0d5522e09f35f3ae6f6f4540a97bb0e612eeb5f404c4ca4fe libcap-devel-2.48-10.el9_7.1.s390x.rpm SHA-256: 4ff2d499196dfb8e094b36d55780327145f83896175c1b8366afda35781962e7 Red Hat Enterprise Linux for Power, little endian 9 SRPM libcap-2.48-10.el9_7.1.src.rpm SHA-256: cd7b587671c0160d85802c044be0dc5a61366db815656a2a4210067a2d2c7303 ppc64le libcap-2.48-10.el9_7.1.ppc64le.rpm SHA-256: d9b3609a24a45a47919d9eafd3099d10f64b2b89b0c51c686386bb1336c3b5dd libcap-debuginfo-2.48-10.el9_7.1.ppc64le.rpm SHA-256: 54788d0d3756ce7b526ecd66f368dc376dafa69a49ef5caa050a7cf0e355611e libcap-debuginfo-2.48-10.el9_7.1.ppc64le.rpm SHA-256: 54788d0d3756ce7b526ecd66f368dc376dafa69a49ef5caa050a7cf0e355611e libcap-debugsource-2.48-10.el9_7.1.ppc64le.rpm SHA-256: 1fa8207926f6b57e9c14d11fe33d2fc2d89f6d2ccfe1903d3d9af189842501b4 libcap-debugsource-2.48-10.el9_7.1.ppc64le.rpm SHA-256: 1fa8207926f6b57e9c14d11fe33d2fc2d89f6d2ccfe1903d3d9af189842501b4 libcap-devel-2.48-10.el9_7.1.ppc64le.rpm SHA-256: 578f54f012fc6e6ad980353d75d937993205c6f1cccecfb8b050e6d5a136e8cf Red Hat Enterprise Linux for ARM 64 9 SRPM libcap-2.48-10.el9_7.1.src.rpm SHA-256: cd7b587671c0160d85802c044be0dc5a61366db815656a2a4210067a2d2c7303 aarch64 libcap-2.48-10.el9_7.1.aarch64.rpm SHA-256: 3ea8b606ad8357faca4e134858c09ee824bc5c625caf1214a8f85412c997c007 libcap-debuginfo-2.48-10.el9_7.1.aarch64.rpm SHA-256: 81bb5f04b89800d99076eee69cb9eab2f17ac9086e2051f94f71671d176df1c5 libcap-debuginfo-2.48-10.el9_7.1.aarch64.rpm SHA-256: 81bb5f04b89800d99076eee69cb9eab2f17ac9086e2051f94f71671d176df1c5 libcap-debugsource-2.48-10.el9_7.1.aarch64.rpm SHA-256: 60bb3e33ab1e4e7f96264440987663a44f5c70a78210e1bb076345a30a711985 libcap-debugsource-2.48-10.el9_7.1.aarch64.rpm SHA-256: 60bb3e33ab1e4e7f96264440987663a44f5c70a78210e1bb076345a30a711985 libcap-devel-2.48-10.el9_7.1.aarch64.rpm SHA-256: 310abcdacc62873a5e95ba54ca22dcb6e14c2ebb9d5ec3bcde8f81f4179f85f8 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article