CVE-2026-71227
EUVD-2026-5333705.08.2026, 13:24
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | hardened_images | - |
| redhat | openshift_container_platform | 4.0 |
| smuellerdd | libkcapi | 0.12.0 ≤ 𝑥 < 1.5.1 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
| redhat | enterprise_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Red Hat Enterprise Linux Releases
Common Weakness Enumeration
References