A flaw was found in libcap.
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege esca
What happened
A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controlled file. By doing so, capabilities can be injected into or stripped from unintended executables, leading to privilege escalation.
Does it affect you
Not enough information
No products recorded, so this cannot be matched against anything.
What to do
- Follow the vendor advisory for the fixed release and any interim mitigation.
access.redhat.com - Follow the vendor advisory for the fixed release and any interim mitigation.
access.redhat.com - Follow the vendor advisory for the fixed release and any interim mitigation.
bugzilla.redhat.com
Vendor's affected list
- rhel
- Exactly 8.0
Sources
A verdict here is derived from what you told us and what the vendor published. It is not an assessment of your environment. Why we never say you are safe.