Denial of Service Vulnerability in libkcapi Affecting Applications Using AIO Interface
CVE-2026-71227
5.1MEDIUM
What is CVE-2026-71227?
A flaw has been identified in libkcapi, where a local attacker can manipulate applications leveraging the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after encountering a prior completion error, the function _kcapi_aio_read_all() may enter a state where it waits indefinitely, causing the application or thread to become unresponsive. This vulnerability poses significant risks to application stability and can be exploited to disrupt service availability.
References
CVSS V3.1
Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.