libcap version 2.78 was released to fix CVE-2026-4878, a time-of-check/time-of-use privilege escalation vulnerability affecting releases from 2.04 through 2.77. The flaw was described as a local issue with a CVSS 3.1 score of 7.0 and vector AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H, with impact on confidentiality, integrity, and availability. Andrew G. Morgan said the fix is available publicly in commit 286ace1259992bd0c5d9016715833f2e148ac596, and that no embargo remained because the code was already public.
Discussion on the oss-security list added that the vulnerability had been documented in a private Red Hat Bugzilla entry and was expected to receive a GitHub advisory later in the week. In follow-up, Christian Göttsche asked whether the updated code intentionally permits changing file capabilities for all file types, rather than only regular files, when the caller has read permissions. Morgan also said earlier attempts to report the issue privately to the Openwall list failed after his messages bounced and the notices were filtered into Gmail spam.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Andrew G. Morgan said the GitHub security advisory and libcap release notes were updated to fully document CVE-2026-4878 publicly. The advisory rated the TOCTOU privilege escalation flaw as CVSS 7.0 and linked the already-public fix commit.
In follow-up discussion, Christian Göttsche asked whether the new code intentionally permits changing file capabilities for all file types, not only regular files, when the caller has read permissions. Morgan responded in the thread while also noting earlier attempts to report the issue privately to Openwall had failed due to bounced emails being filtered as spam.
The public disclosure described the vulnerability as a local TOCTOU privilege escalation issue with CVSS 7.0 and vector AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H. Morgan said there was no embargo because the code was already public, referenced a private Red Hat Bugzilla entry, and said a GitHub advisory would follow later that week.
Andrew G. Morgan announced libcap 2.78 as a fix for a TOCTOU privilege escalation vulnerability tracked as CVE-2026-4878. The flaw affects libcap versions 2.04 through 2.77, and the public fix was identified as commit 286ace1259992bd0c5d9016715833f2e148ac596.
An upstream libcap commit introduced a fix for the TOCTOU race condition in cap_set_file() by switching to safer file-descriptor-based handling, blocking symlink abuse, and validating regular files. The patch also updated tests to verify safe capability setting and failure when removing capabilities through a symlinked path.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
10 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourceseclists.org
Open sourcegit.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.