<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:11:55 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:67265 — Moderate: libkcapi security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:67265</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libkcapi, AlmaLinux:9: libkcapi-hmaccalc&lt;/p&gt;
&lt;p&gt;libkcapi allows user-space to access the Linux kernel crypto API. This library uses the netlink interface and exports easy to use APIs so that a developer does not need to consider the low-level netlink interface handling. The library does not implement any cipher algorithms. All consumer requests are sent to the kernel for processing. Results from the kernel crypto API are returned to the consumer via the library API. The kernel interface and therefore this library can be used by unprivileged processes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries (CVE-2026-71225)
  * libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path (CVE-2026-71226)
  * libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return (CVE-2026-71227)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* libkcapi: AEAD Decrypt Auth Check Skipped for Zero-Length Input in `kcapi-enc` [almalinux-9.8.z] (JIRA:AlmaLinux-242667)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libkcapi, AlmaLinux:9: libkcapi-hmaccalc&lt;/p&gt;
&lt;p&gt;libkcapi allows user-space to access the Linux kernel crypto API. This library uses the netlink interface and exports easy to use APIs so that a developer does not need to consider the low-level netlink interface handling. The library does not implement any cipher algorithms. All consumer requests are sent to the kernel for processing. Results from the kernel crypto API are returned to the consumer via the library API. The kernel interface and therefore this library can be used by unprivileged processes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries (CVE-2026-71225)
  * libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path (CVE-2026-71226)
  * libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return (CVE-2026-71227)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* libkcapi: AEAD Decrypt Auth Check Skipped for Zero-Length Input in `kcapi-enc` [almalinux-9.8.z] (JIRA:AlmaLinux-242667)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:67265</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-71225</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-71225</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: libkcapi, Alpaquita:25: libkcapi, Alpaquita:stream: libkcapi&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: libkcapi, Alpaquita:25: libkcapi, Alpaquita:stream: libkcapi&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-71225</guid>
    </item>
    <item>
      <title>EUVD-2026-372774</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-372774</link>
      <description>EUVD-2026-372774</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-372774</guid>
    </item>
    <item>
      <title>fkie_cve-2026-71225</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71225</link>
      <description>&lt;p&gt;A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-71225</guid>
    </item>
    <item>
      <title>GHSA-qv62-qmw8-96h9</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qv62-qmw8-96h9</link>
      <description>&lt;p&gt;A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qv62-qmw8-96h9</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-71225 — Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-71225</link>
      <description>msrc_CVE-2026-71225</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-71225</guid>
    </item>
    <item>
      <title>OESA-2026-3575 — libkcapi security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3575</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: libkcapi, openEuler:24.03-LTS-SP1: libkcapi, openEuler:24.03-LTS-SP3: libkcapi, openEuler:24.03-LTS-SP4: libkcapi, openEuler:20.03-LTS-SP4: libkcapi&lt;/p&gt;
&lt;p&gt;The Linux kernel exports a Netlink interface of type AF_ALG to allow user space to utilize the kernel crypto API. libkcapi uses this Netlink interface and exports easy to use APIs so that a developer does not need to consider the low-level Netlink interface handling. The library does not implement any cipher algorithms. All consumer requests are sent to the kernel for processing. Results from the kernel crypto API are returned to the consumer via the library API.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.(CVE-2026-71225)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: libkcapi, openEuler:24.03-LTS-SP1: libkcapi, openEuler:24.03-LTS-SP3: libkcapi, openEuler:24.03-LTS-SP4: libkcapi, openEuler:20.03-LTS-SP4: libkcapi&lt;/p&gt;
&lt;p&gt;The Linux kernel exports a Netlink interface of type AF_ALG to allow user space to utilize the kernel crypto API. libkcapi uses this Netlink interface and exports easy to use APIs so that a developer does not need to consider the low-level Netlink interface handling. The library does not implement any cipher algorithms. All consumer requests are sent to the kernel for processing. Results from the kernel crypto API are returned to the consumer via the library API.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.(CVE-2026-71225)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3575</guid>
    </item>
    <item>
      <title>RHSA-2026:56985 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:56985</link>
      <description>&lt;p&gt;libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:56985</guid>
    </item>
    <item>
      <title>RHSA-2026:67265 — Red Hat Security Advisory: libkcapi security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:67265</link>
      <description>&lt;p&gt;libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:67265</guid>
    </item>
    <item>
      <title>RLSA-2026:67265 — Moderate: libkcapi security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:67265</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: libkcapi&lt;/p&gt;
&lt;p&gt;libkcapi allows user-space to access the Linux kernel crypto API.  This library uses the netlink interface and exports easy to use APIs so that a developer does not need to consider the low-level netlink interface handling.  The library does not implement any cipher algorithms.  All consumer requests are sent to the kernel for processing.  Results from the kernel crypto API are returned to the consumer via the library API.  The kernel interface and therefore this library can be used by unprivileged processes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries (CVE-2026-71225)&lt;/p&gt;
&lt;p&gt;* libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path (CVE-2026-71226)&lt;/p&gt;
&lt;p&gt;* libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return (CVE-2026-71227)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* libkcapi: AEAD Decrypt Auth Check Skipped for Zero-Length Input in `kcapi-enc` [rhel-9.8.z] (JIRA:Rocky Linux-242667)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: libkcapi&lt;/p&gt;
&lt;p&gt;libkcapi allows user-space to access the Linux kernel crypto API.  This library uses the netlink interface and exports easy to use APIs so that a developer does not need to consider the low-level netlink interface handling.  The library does not implement any cipher algorithms.  All consumer requests are sent to the kernel for processing.  Results from the kernel crypto API are returned to the consumer via the library API.  The kernel interface and therefore this library can be used by unprivileged processes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries (CVE-2026-71225)&lt;/p&gt;
&lt;p&gt;* libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path (CVE-2026-71226)&lt;/p&gt;
&lt;p&gt;* libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return (CVE-2026-71227)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* libkcapi: AEAD Decrypt Auth Check Skipped for Zero-Length Input in `kcapi-enc` [rhel-9.8.z] (JIRA:Rocky Linux-242667)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:67265</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-71225</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71225</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:FIPS:16.04:LTS: libkcapi, Ubuntu:18.04:LTS: libkcapi, Ubuntu:Pro:FIPS-updates:18.04:LTS: libkcapi, Ubuntu:Pro:FIPS:18.04:LTS: libkcapi, Ubuntu:20.04:LTS: libkcapi, Ubuntu:Pro:FIPS-updates:20.04:LTS: libkcapi, Ubuntu:Pro:FIPS:20.04:LTS: libkcapi, Ubuntu:22.04:LTS: libkcapi, Ubuntu:Pro:FIPS-preview:22.04:LTS: libkcapi, Ubuntu:Pro:FIPS-updates:22.04:LTS: libkcapi and 2 more&lt;/p&gt;
&lt;p&gt;A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:FIPS:16.04:LTS: libkcapi, Ubuntu:18.04:LTS: libkcapi, Ubuntu:Pro:FIPS-updates:18.04:LTS: libkcapi, Ubuntu:Pro:FIPS:18.04:LTS: libkcapi, Ubuntu:20.04:LTS: libkcapi, Ubuntu:Pro:FIPS-updates:20.04:LTS: libkcapi, Ubuntu:Pro:FIPS:20.04:LTS: libkcapi, Ubuntu:22.04:LTS: libkcapi, Ubuntu:Pro:FIPS-preview:22.04:LTS: libkcapi, Ubuntu:Pro:FIPS-updates:22.04:LTS: libkcapi and 2 more&lt;/p&gt;
&lt;p&gt;A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71225</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3322 — Red Hat Enterprise Linux (libkcapi): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3322</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen, Daten zu manipulieren, Speicherbeschädigungen zu verursachen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen, Daten zu manipulieren, Speicherbeschädigungen zu verursachen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3322</guid>
    </item>
  </channel>
</rss>
