https://seclists.org/oss-sec/2026/q2/58: libcap-2.77 (since libcap-2.04) has TOCTOU privilege escalation issue
Published Apr 9, 2026
·Updated
Affected Software
1 affected component
libcap libcap>=2.04<=2.77
Frequently Asked Questions
1
What is the severity of CVE-2026-XXXX?
The severity of CVE-2026-XXXX is categorized as high due to its potential for privilege escalation.
2
How do I fix CVE-2026-XXXX?
To fix CVE-2026-XXXX, upgrade to libcap version 2.78 or later.
3
What is a TOCTOU issue in the context of CVE-2026-XXXX?
A TOCTOU (Time of Check to Time of Use) issue occurs when a system checks a condition before an operation but an attacker can alter the state before the operation is executed.
4
Which version of libcap is affected by CVE-2026-XXXX?
CVE-2026-XXXX affects libcap versions from 2.04 up to 2.77.
5
Is there a workaround for CVE-2026-XXXX before upgrading?
There is no known effective workaround for CVE-2026-XXXX, so upgrading to the patched version is recommended.