CVE-2026-4878

Red Hat Security Advisory: Red Hat AI Inference Server 3.3.5 (ROCm)

Beschreibung

Ein Fehler wurde in libcap gefunden. Ein lokaler unprivilegierter Benutzer kann eine Time-of-check-to-time-of-use (TOCTOU)-Racebedingung im `cap_set_file()`-Funktion ausnutzen. Dadurch kann ein Angreifer mit Schreibzugriff auf einem übergeordneten Verzeichnis die Aktualisierung der Dateifähigkeiten auf eine von ihm kontrollierte Datei umleiten. Auf diese Weise können Fähigkeiten in oder von unbeabsichtigten ausführbaren Dateien eingefügt oder entfernt werden, was zu einer Erhöhung der Privilegien führt.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.0
Quelle: nvd-v3
10.7 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.2 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-06-25 19:30 UTC
CWE-367

Weakness-Klassen (CWE)

  • CWE-367Base

    Time-of-check Time-of-use (TOCTOU) Race Condition

    The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-09-09 13:20 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/4xxx/CVE-2026-4878.json">CVE-2026-4878</a>
  2. CVE Modified2026-09-08 16:18 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/4xxx/CVE-2026-4878.json">CVE-2026-4878</a>
  3. CVE Modified2026-09-08 14:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/4xxx/CVE-2026-4878.json">CVE-2026-4878</a>
  4. CVE Modified2026-09-07 21:17 UTC· secalert@redhat.com
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/4xxx/CVE-2026-4878.json">CVE-2026-4878</a>
  5. CVE Modified2026-09-07 13:20 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/4xxx/CVE-2026-4878.json">CVE-2026-4878</a>

Betroffene Betriebssysteme

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux_ai3.0

  • linux

    ubuntu / jqbionic

  • linux

    ubuntu / jqfocal

  • linux

    ubuntu / popplerjammy

  • linux

    ubuntu / popplernoble

  • linux

    ubuntu / popplerquesting

  • linux

    ubuntu / popplerresolute

  • other

    siemens / sinec_os

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • bitnami

    python-min3.11.0

  • bitnami

    python-min3.12.0

  • bitnami

    python-min3.13.0

  • bitnami

    python-min3.14.0

  • cryptography.io

    cryptography45.0.0 – 46.0.7

  • encode

    starlette0.8.3 – 1.0.1

  • encode

    starlette1.1.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

  • jqlang

    jq2026-04-12

  • libcap_project

    libcap

  • libsndfile_project

    libsndfile

  • libtiff

    libtiff

  • openbsd

    openssh10.3

  • openexr

    openexr3.1.0 – 3.2.7

  • openexr

    openexr3.3.0 – 3.3.9

  • openexr

    openexr3.4.0 – 3.4.9

  • pyasn1

    pyasn10.6.2

  • pyjwt_project

    pyjwt2.13.0

  • pypi

    vllm0.0.1

  • pypi

    vllm0.1.0

  • pypi

    vllm0.10.0

  • pypi

    vllm0.10.1

  • pypi

    vllm0.10.1.1

  • pypi

    vllm0.10.2

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-4878
Red Hat Security Advisory: Red Hat AI Inference Server 3.3.5 (ROCm) — CVE-2026-4878 | NEOSEC Intel