Libcap is a narrowly scoped library that provides user-space interfaces for managing POSIX capability sets on Linux systems, serving as a foundational component for privilege-management tooling across the operating system ecosystem. The library's vulnerability surface reflects its focused mandate around capability manipulation and system interfaces, with the durable signal centered on the mechanisms and parsing logic inherent to capability management. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libcap over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4878HIGH A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker w | Apr 9, 2026 | 7.0 | 29 | NO | NO |
CVE-2023-2603HIGH A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB. | Jun 6, 2023 | 7.8 | 24 | NO | NO |
CVE-2011-4099MEDIUM The capsh program in libcap before 2.22 does not change the current working directory when the --chroot option is specified, which allows local users to bypass the chroot restricti | Feb 8, 2014 | 4.6 | 17 | NO | NO |
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exha | Jun 6, 2023 | 3.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libcap.
Media articles that mention a CVE ID that affects a product developed by Libcap — matched by CVE ID, not by vendor name.