Record summary

CVE-2026-71227 has a selected CVSS score of 5.1 (medium).

Description

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List

Affected products and versions

6
ProductSourceVersion rangeStatus

Red Hat Enterprise Linux 10

Browse Red Hat / Red Hat Enterprise Linux 10libkcapi

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 8

Browse Red Hat / Red Hat Enterprise Linux 8libkcapi

Default status: affected

CVE ListVersion data not supplied

Red Hat Enterprise Linux 9

Browse Red Hat / Red Hat Enterprise Linux 9libkcapi

Default status: affected

CVE ListVersion data not supplied

Red Hat Hardened Images

Browse Red Hat / Red Hat Hardened Imageslibkcapi

Default status: affected

CVE ListVersion data not supplied

Red Hat OpenShift Container Platform 4

Browse Red Hat / Red Hat OpenShift Container Platform 4rhcos

Default status: affected

CVE ListVersion data not supplied

Default status: unaffected

CVE List0.12.0 to < 1.5.1affected

References

3