cbcvebase.

Debian Libcap2 vulnerabilities

5 known vulnerabilities affecting debian/libcap2.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2LOW2

Vulnerabilities

Page 1 of 1
CVE-2026-4878P3MEDIUMCVSS 6.7fixed in libcap2 1:2.78-1 (forky)2026
CVE-2026-4878 [MEDIUM] CVE-2026-4878: libcap2 bookworm: open bullseye: open forky: resolved (fixed in 1:2.78-1) sid: resolved (fixed in 1:2.78-1) trixie: open
debian
CVE-2023-2603P3HIGHCVSS 7.8fixed in libcap2 1:2.66-4 (bookworm)2023
CVE-2023-2603 [HIGH] CVE-2023-2603: libcap2 - A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() f... A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB. Scope: local bookworm: resolved (fixed in 1:2.66-4) bullseye: resolved (fixed in 1:2.44-1+deb11u1) forky: resolved (fixed in 1:2.66-4) sid: resolved (fixed in 1:2.66-4) trixie: resolved (fixed in 1:2.66-4)
debian
CVE-2025-1390P4MEDIUMCVSS 6.1fixed in libcap2 1:2.66-4+deb12u1 (bookworm)2025
CVE-2025-1390 [MEDIUM] CVE-2025-1390: libcap2 - The PAM module pam_cap.so of libcap configuration supports group names starting ... The PAM module pam_cap.so of libcap configuration supports group names starting with “@”, during actual parsing, configurations not starting with “@” are incorrectly recognized as group names. This may result in nonintended users being granted an inherited capability set, potentially leading to security risks. Attackers can exploit this vulnerability to achieve loca
debian
CVE-2011-4099P4LOWCVSS 4.6fixed in libcap2 1:2.22-1 (bookworm)2011
CVE-2011-4099 [MEDIUM] CVE-2011-4099: libcap2 - The capsh program in libcap before 2.22 does not change the current working dire... The capsh program in libcap before 2.22 does not change the current working directory when the --chroot option is specified, which allows local users to bypass the chroot restrictions via unspecified vectors. Scope: local bookworm: resolved (fixed in 1:2.22-1) bullseye: resolved (fixed in 1:2.22-1) forky: resolved (fixed in 1:2.22-1) sid: resolved (fixed in 1:2.22-1
debian
CVE-2023-2602P4LOWCVSS 3.3fixed in libcap2 1:2.66-4 (bookworm)2023
CVE-2023-2602 [LOW] CVE-2023-2602: libcap2 - A vulnerability was found in the pthread_create() function in libcap. This issue... A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory. Scope: local bookworm: resolved (fixed in 1:2.66-4) bullseye: resolved (fixed in 1:2.44-1+deb11u1) forky: resolved (fixed in 1:2.66-4) sid: resolved (fixed in 1:2.66-4
debian