mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-10-03 07:21:45 -09:00
Fixes the following vulnerability:
- CVE-2026-4878:
A flaw was found in libcap. A local unprivileged user can exploit a
Time-of-check-to-time-of-use (TOCTOU) race condition in the
`cap_set_file()` function. This allows an attacker with write access
to a parent directory to redirect file capability updates to an
attacker-controlled file. By doing so, capabilities can be injected
into or stripped from unintended executables, leading to privilege
escalation.
For more information, see:
- https://www.cve.org/CVERecord?id=CVE-2026-4878
- https://security-tracker.debian.org/tracker/CVE-2026-4878
- https://git.kernel.org/pub/scm/libs/libcap/libcap.git/commit/?id=286ace1259992bd0c5d9016715833f2e148ac596
(cherry picked from commit 76e4d8e3df)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>