Improper IV Reuse in libkcapi Affects Encryption in Applications
CVE-2026-71225

6.5MEDIUM

What is CVE-2026-71225?

A vulnerability has been identified in libkcapi that affects the integrity of symmetric cipher operations. Specifically, the library improperly reuses the Initialization Vector (IV) during one-shot symmetric cipher operations for inputs larger than 64 KiB when utilizing stateful modes like Counter (CTR) or Cipher Block Chaining (CBC). This IV reuse can lead to significant weaknesses in data confidentiality, allowing a remote attacker to exploit applications that depend on libkcapi by sending specially crafted large inputs. As a result, this flaw can reveal patterns in the encrypted plaintext and jeopardize the integrity of the cryptographic process itself.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Found by AISLE in partnership with Red Hat.
.