[CLSA-2026:1777944214] libcap: Fix of CVE-2026-4878
Type:
security
Severity:
Important
Release date:
2026-05-05 21:06:41 UTC
Description:
- CVE-2026-4878: fix TOCTOU race in cap_set_file() by performing xattr writes via an O_NOFOLLOW file descriptor instead of the user-supplied path
Updated packages:
  • libcap-2.22-11.el7.tuxcare.els2.i686.rpm
    sha:f710cc5a2cf2a8c53aa46cf87ab8dec1f5185bb8f9c496daef8f0dae9f5fe3b5
  • libcap-2.22-11.el7.tuxcare.els2.x86_64.rpm
    sha:a0c4c844e82ab4974808c07583569aa311ab86379fcda2c19fc1d407944474a4
  • libcap-devel-2.22-11.el7.tuxcare.els2.i686.rpm
    sha:10883223e7395c70981eb29f54174b5a4e932b16ba109002047b070cac5606e5
  • libcap-devel-2.22-11.el7.tuxcare.els2.x86_64.rpm
    sha:e5bde3f531d367fe38d50af088e0d7bb918b6aeeb41a3b1970d97e52764005fe
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.