CVE-2026-71227
Published: August 6, 2026Last modified: August 26, 2026
Description
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 5.1 |
| Attack Vector | LOCAL |
| Attack complexity | HIGH |
| Privileges required | NONE |
| User interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality | NONE |
| Integrity impact | NONE |
| Availability impact | HIGH |
| Vector | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 23 LTS | libkcapi | Unknown (1.4.0-r0) |
| 25 LTS | libkcapi | Fixed (1.5.1-r0) | |
| Stream | libkcapi | Fixed (1.5.1-r0) |