[CLSA-2026:1777941808] libcap: Fix of CVE-2026-4878
Type:
security
Severity:
Important
Release date:
2026-05-05 00:43:42 UTC
Description:
- CVE-2026-4878: fix TOCTOU race in cap_set_file() by performing xattr writes via an O_NOFOLLOW file descriptor instead of the user-supplied path
Updated packages:
  • libcap-2.22-11.el7.tuxcare.els2.i686.rpm
    sha:b028e686451d0853bc8afe7a6de84718e8eb37e8dd44ba697e52a848aae3f5c3
  • libcap-2.22-11.el7.tuxcare.els2.x86_64.rpm
    sha:797de5625a4798e0d051199fb6c4e7655aa83e6a0f000b2fcc3a421d303e1c6a
  • libcap-devel-2.22-11.el7.tuxcare.els2.i686.rpm
    sha:01b6b8a10733618fb2d695a773f82a6c16400c00daae3a2d9dc5a5d92cfa314f
  • libcap-devel-2.22-11.el7.tuxcare.els2.x86_64.rpm
    sha:c4a2cc63a0cf6a2f04ce2da759f6b2a67d1141b62882c356ecf26fc1740bcc1f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.