#1143974 libkcapi: CVE-2026-71225 CVE-2026-71226 CVE-2026-71227

Package:
src:libkcapi
Source:
src:libkcapi
Submitter:
Salvatore Bonaccorso
Date:
2026-09-23 06:53:02 UTC
Severity:
normal
Tags:
#1143974#5
Date:
2026-08-09 06:51:44 UTC
From:
To:
Hi,

The following vulnerabilities were published for libkcapi.

Only reference at time of writing were the Red Hat bugreports (see
security-tracker pages), can you check upstream if they are known and
tracked?

CVE-2026-71225[0]:
| A flaw was found in libkcapi. When performing one-shot symmetric
| cipher operations on large inputs (over 64 KiB) in stateful modes
| such as Counter (CTR) or Cipher Block Chaining (CBC), the library
| improperly reuses the Initialization Vector (IV) for each internal
| data chunk. A remote attacker could potentially exploit this by
| making an application that uses libkcapi process specially crafted
| large inputs. This can lead to a significant weakening of data
| confidentiality, as the repeated IV use can expose relationships in
| encrypted plaintext, and may also affect data integrity by causing
| incorrect cryptographic processing.


CVE-2026-71226[1]:
| Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's
| one-shot AIO path can return an error before all submitted IOCBs are
| drained, allowing later kernel writes into caller-owned output
| buffers.


CVE-2026-71227[2]:
| A flaw was found in libkcapi. A local attacker can influence an
| application that uses the Asynchronous Input/Output (AIO) interface.
| By reusing an AIO-enabled handle after a prior completion error, the
| _kcapi_aio_read_all() function can enter a non-terminating wait
| loop. This can lead to a persistent denial of service, making the
| affected application or thread unresponsive.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-71225
https://www.cve.org/CVERecord?id=CVE-2026-71225
[1] https://security-tracker.debian.org/tracker/CVE-2026-71226
https://www.cve.org/CVERecord?id=CVE-2026-71226
[2] https://security-tracker.debian.org/tracker/CVE-2026-71227
https://www.cve.org/CVERecord?id=CVE-2026-71227

Regards,
Salvatore

#1143974#10
Date:
2026-09-19 15:08:27 UTC
From:
To:
close 1143974 1.5.1-1
thanks

sorry - didn't check the bts after adopting the package and before
uploading 1.5.1-1, but I've amended the 1.5.1-1 changelog in git, so
next upload will have them.

Regards,
Daniel

#1143974#21
Date:
2026-09-19 15:34:22 UTC
From:
To:
Hi Daniel,

Thanks for the update. Do you have references for the fixes? When we
last filled he bugs, I think only the Red Hat bugzilla entries were
available, but no references to upstream fixes at all.

Regards,
Salvatore

#1143974#31
Date:
2026-09-23 06:51:35 UTC
From:
To:
Hi Daniel,

Thanks a lot, checked and we did backfill the refereces back to
security-tracker.

We had a look, does not seem to warrant a DSA though. Could you
prepare the update for the next point release happening on 14th
November?

Regards,
Salvatore