libkcapi-1.4.0-3.el9_8.ML.1
エラータID: AXSA:2026-1845:02
libkcapi allows user-space to access the Linux kernel crypto API. This library uses the netlink interface and exports easy to use APIs so that a developer does not need to consider the low-level netlink interface handling. The library does not implement any cipher algorithms. All consumer requests are sent to the kernel for processing. Results from the kernel crypto API are returned to the consumer via the library API. The kernel interface and therefore this library can be used by unprivileged processes.
Security Fix(es):
* libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries (CVE-2026-71225)
* libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi's one-shot AIO path (CVE-2026-71226)
* libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return (CVE-2026-71227)
Bug Fix(es) and Enhancement(s):
* libkcapi: AEAD Decrypt Auth Check Skipped for Zero-Length Input in `kcapi-enc` [rhel-9.8.z] (JIRA:RHEL-242667)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-71225
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.
CVE-2026-71226
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
CVE-2026-71227
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.
Update packages.
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.
N/A
SRPMS
- libkcapi-1.4.0-3.el9_8.ML.1.src.rpm
MD5: 1ff648a98c13a36d83807f0578c83cf8
SHA-256: df8fe6894cb09cc3582dcafc3feb944d7e3f1a740c9118f3feaddacdcbecdd83
Size: 359.53 kB
Asianux Server 9 for x86_64
- libkcapi-1.4.0-3.el9_8.ML.1.i686.rpm
MD5: 216a80b4cb32542c245041b9f854df92
SHA-256: cb091d01f84b1a16e4804b68a53d1dbaa65a81ce8c4b0e75b7a9f1adec3023e8
Size: 46.25 kB - libkcapi-1.4.0-3.el9_8.ML.1.x86_64.rpm
MD5: 209590da747ec2dc8d27126100aba397
SHA-256: 904305f059197be5327b681f5891d7c6ae2d37e8e40b5f52ae543cb2139a6bbf
Size: 44.83 kB - libkcapi-hmaccalc-1.4.0-3.el9_8.ML.1.x86_64.rpm
MD5: a88410d16c080d723e96ee692369670e
SHA-256: 8509f0798c5d7b1d4ee080e919d707307ad0129943841e9e20877f45a0217df0
Size: 23.05 kB