Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71227

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 5.1
EPSS Низкий

Описание

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.

Меры по смягчению последствий

To mitigate this issue, applications should avoid initializing libkcapi handles with KCAPI_INIT_AIO if AIO functionality is not strictly required. If AIO must be used, applications should destroy and reinitialize libkcapi handles after any AIO completion error, rather than reusing them for subsequent AIO operations.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libkcapiAffected
Red Hat Enterprise Linux 8libkcapiAffected
Red Hat Enterprise Linux 9libkcapiAffected
Red Hat OpenShift Container Platform 4openshift/ose-rhel-coreos-9Fix deferred
Red Hat Hardened Imageslibkcapi-main-1.5.1-0.1.hum1FixedRHSA-2026:5698519.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2462867libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return

EPSS

Процентиль: 6%
0.00164
Низкий

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.1
ubuntu
26 дней назад

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.

CVSS3: 5.1
nvd
26 дней назад

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.

CVSS3: 5.1
msrc
23 дня назад

Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return

CVSS3: 5.1
debian
26 дней назад

A flaw was found in libkcapi. A local attacker can influence an applic ...

CVSS3: 5.1
github
26 дней назад

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.

EPSS

Процентиль: 6%
0.00164
Низкий

5.1 Medium

CVSS3

Уязвимость CVE-2026-71227