Red Hat disclosed CVE-2026-4878, an Important local privilege-escalation flaw in libcap caused by a time-of-check-to-time-of-use race in the cap_set_file() function. The bug allows a local unprivileged attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file, potentially injecting or stripping capabilities from unintended executables. Red Hat said the issue can be triggered when privileged processes such as setcap or container tooling operate on attacker-influenced paths, assigned it a CVSS v3 score of 6.7, and classified it as CWE-367. No mitigation meeting Red Hat's criteria was listed, and the issue was credited to Ali Raza.
Red Hat issued security errata across multiple product streams for Red Hat Enterprise Linux 8, 9, and 10, including standard, Extended Update Support, SAP, telecommunications, mission-critical, and Extended Life Cycle channels. Published fixes include libcap-2.69-7.el10_1.1 and 2.69-7.el10_2.1 for RHEL 10, libcap-2.48-10.el9_7.1 and 2.48-10.el9_8.1 for RHEL 9, and libcap-2.48-4.el8_6.1 plus 2.48-5.el8_8.1 for affected RHEL 8 streams. Red Hat advised customers to apply the updated packages through the relevant RHSA advisories to remediate the vulnerability.

Get the actors, campaigns, and ATT&CK mapping behind it.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:12441 to remediate CVE-2026-4878 in Red Hat Enterprise Linux 9, publishing updated libcap packages version 2.48-10.el9_7.1 for standard and extended support variants.
Red Hat issued RHSA-2026:12423 to fix CVE-2026-4878 in Red Hat Enterprise Linux 10, releasing updated libcap packages version 2.69-7.el10_1.1 across multiple architectures and support channels.
Red Hat published its CVE entry for CVE-2026-4878, describing an Important local privilege-escalation vulnerability in libcap caused by a TOCTOU race in cap_set_file(). Red Hat credited Ali Raza with reporting the issue.
Red Hat last modified its CVE-2026-4878 entry after issuing fixes across multiple RHEL product streams from April through June 2026.
Red Hat issued RHSA-2026:24346 for Red Hat Enterprise Linux 8.6 support channels, publishing libcap version 2.48-4.el8_6.1 to fix CVE-2026-4878.
Red Hat issued RHSA-2026:22957 for affected Red Hat Enterprise Linux 8.8 channels, releasing libcap version 2.48-5.el8_8.1 to remediate CVE-2026-4878.
Red Hat released RHSA-2026:19456 to fix CVE-2026-4878 in Red Hat Enterprise Linux 10.0 Extended Update Support.
Red Hat issued RHSA-2026:19346 for Red Hat Enterprise Linux 9, shipping updated libcap packages version 2.48-10.el9_8.1 to address CVE-2026-4878 across multiple architectures and support streams.
Red Hat issued RHSA-2026:19130 for Red Hat Enterprise Linux 10, providing another libcap security update for CVE-2026-4878 with package version 2.69-7.el10_2.1 across standard, EUS, 4-year, and ELC channels.
Red Hat released RHSA-2026:13285 to fix CVE-2026-4878 in Red Hat Enterprise Linux 8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.