libcap could be made to modify capabilities on arbitrary files.
Software Description:
- libcap2: POSIX 1003.1e capabilities library
Details:
USN-8193-1 fixed a vulnerability in libcap. This update provides the
corresponding update for Ubuntu 14.04 LTS, Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS.
Original advisory details:
Ali Raza discovered that libcap incorrectly handled file capability
updates. A local attacker could possibly use this issue to inject or strip
capabilities into arbitrary executables and escalate privileges.
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS
libcap-dev 1:2.32-1ubuntu0.2+esm1
Available with Ubuntu Pro
libcap2 1:2.32-1ubuntu0.2+esm1
Available with Ubuntu Pro
libcap2-bin 1:2.32-1ubuntu0.2+esm1
Available with Ubuntu Pro
libpam-cap 1:2.32-1ubuntu0.2+esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
libcap-dev 1:2.25-1.2ubuntu0.1~esm2
Available with Ubuntu Pro
libcap2 1:2.25-1.2ubuntu0.1~esm2
Available with Ubuntu Pro
libcap2-bin 1:2.25-1.2ubuntu0.1~esm2
Available with Ubuntu Pro
libpam-cap 1:2.25-1.2ubuntu0.1~esm2
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libcap-dev 1:2.24-12ubuntu0.1~esm2
Available with Ubuntu Pro
libcap2 1:2.24-12ubuntu0.1~esm2
Available with Ubuntu Pro
libcap2-bin 1:2.24-12ubuntu0.1~esm2
Available with Ubuntu Pro
libpam-cap 1:2.24-12ubuntu0.1~esm2
Available with Ubuntu Pro
Ubuntu 14.04 LTS
libcap-dev 1:2.24-0ubuntu2+esm2
Available with Ubuntu Pro
libcap2 1:2.24-0ubuntu2+esm2
Available with Ubuntu Pro
libcap2-bin 1:2.24-0ubuntu2+esm2
Available with Ubuntu Pro
libpam-cap 1:2.24-0ubuntu2+esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.https://ubuntu.com/security/notices/USN-8193-2
https://ubuntu.com/security/notices/USN-8193-1
CVE-2026-4878
Get the latest Linux and open source security news straight to your inbox.