CVE-2026-71227

Published: August 6, 2026Last modified: August 26, 2026

Description

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.

Severity score breakdown

ParameterValue
Base score5.1
Attack VectorLOCAL
Attack complexityHIGH
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibkcapiUnknown (1.4.0-r0)
25 LTSlibkcapiFixed (1.5.1-r0)
StreamlibkcapiFixed (1.5.1-r0)

References

ON THIS PAGE