<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:45:42 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:67265 — Moderate: libkcapi security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:67265</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libkcapi, AlmaLinux:9: libkcapi-hmaccalc&lt;/p&gt;
&lt;p&gt;libkcapi allows user-space to access the Linux kernel crypto API. This library uses the netlink interface and exports easy to use APIs so that a developer does not need to consider the low-level netlink interface handling. The library does not implement any cipher algorithms. All consumer requests are sent to the kernel for processing. Results from the kernel crypto API are returned to the consumer via the library API. The kernel interface and therefore this library can be used by unprivileged processes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries (CVE-2026-71225)
  * libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path (CVE-2026-71226)
  * libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return (CVE-2026-71227)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* libkcapi: AEAD Decrypt Auth Check Skipped for Zero-Length Input in `kcapi-enc` [almalinux-9.8.z] (JIRA:AlmaLinux-242667)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libkcapi, AlmaLinux:9: libkcapi-hmaccalc&lt;/p&gt;
&lt;p&gt;libkcapi allows user-space to access the Linux kernel crypto API. This library uses the netlink interface and exports easy to use APIs so that a developer does not need to consider the low-level netlink interface handling. The library does not implement any cipher algorithms. All consumer requests are sent to the kernel for processing. Results from the kernel crypto API are returned to the consumer via the library API. The kernel interface and therefore this library can be used by unprivileged processes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries (CVE-2026-71225)
  * libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path (CVE-2026-71226)
  * libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return (CVE-2026-71227)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* libkcapi: AEAD Decrypt Auth Check Skipped for Zero-Length Input in `kcapi-enc` [almalinux-9.8.z] (JIRA:AlmaLinux-242667)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:67265</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-71227</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-71227</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: libkcapi, Alpaquita:25: libkcapi, Alpaquita:stream: libkcapi&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: libkcapi, Alpaquita:25: libkcapi, Alpaquita:stream: libkcapi&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-71227</guid>
    </item>
    <item>
      <title>EUVD-2026-372776</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-372776</link>
      <description>EUVD-2026-372776</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-372776</guid>
    </item>
    <item>
      <title>fkie_cve-2026-71227</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-71227</link>
      <description>&lt;p&gt;A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-71227</guid>
    </item>
    <item>
      <title>GHSA-c5mv-c5vm-62w5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c5mv-c5vm-62w5</link>
      <description>&lt;p&gt;A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c5mv-c5vm-62w5</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-71227 — Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout ret…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-71227</link>
      <description>msrc_CVE-2026-71227</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-71227</guid>
    </item>
    <item>
      <title>OESA-2026-3440 — libkcapi security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3440</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: libkcapi, openEuler:20.03-LTS-SP4: libkcapi, openEuler:22.03-LTS-SP4: libkcapi, openEuler:24.03-LTS-SP1: libkcapi, openEuler:24.03-LTS-SP3: libkcapi&lt;/p&gt;
&lt;p&gt;The Linux kernel exports a Netlink interface of type AF_ALG to allow user space to utilize the kernel crypto API. libkcapi uses this Netlink interface and exports easy to use APIs so that a developer does not need to consider the low-level Netlink interface handling. The library does not implement any cipher algorithms. All consumer requests are sent to the kernel for processing. Results from the kernel crypto API are returned to the consumer via the library API.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Memory Corruption via Uncanceled AIO Requests on Error: libkcapi&amp;amp;apos;s one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.(CVE-2026-71226)&lt;/p&gt;
&lt;p&gt;A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.(CVE-2026-71227)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: libkcapi, openEuler:20.03-LTS-SP4: libkcapi, openEuler:22.03-LTS-SP4: libkcapi, openEuler:24.03-LTS-SP1: libkcapi, openEuler:24.03-LTS-SP3: libkcapi&lt;/p&gt;
&lt;p&gt;The Linux kernel exports a Netlink interface of type AF_ALG to allow user space to utilize the kernel crypto API. libkcapi uses this Netlink interface and exports easy to use APIs so that a developer does not need to consider the low-level Netlink interface handling. The library does not implement any cipher algorithms. All consumer requests are sent to the kernel for processing. Results from the kernel crypto API are returned to the consumer via the library API.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Memory Corruption via Uncanceled AIO Requests on Error: libkcapi&amp;amp;apos;s one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.(CVE-2026-71226)&lt;/p&gt;
&lt;p&gt;A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.(CVE-2026-71227)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3440</guid>
    </item>
    <item>
      <title>RHSA-2026:56985 — Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:56985</link>
      <description>&lt;p&gt;libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:56985</guid>
    </item>
    <item>
      <title>RHSA-2026:67265 — Red Hat Security Advisory: libkcapi security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:67265</link>
      <description>&lt;p&gt;libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:67265</guid>
    </item>
    <item>
      <title>RLSA-2026:67265 — Moderate: libkcapi security, bug fix, and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:67265</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: libkcapi&lt;/p&gt;
&lt;p&gt;libkcapi allows user-space to access the Linux kernel crypto API.  This library uses the netlink interface and exports easy to use APIs so that a developer does not need to consider the low-level netlink interface handling.  The library does not implement any cipher algorithms.  All consumer requests are sent to the kernel for processing.  Results from the kernel crypto API are returned to the consumer via the library API.  The kernel interface and therefore this library can be used by unprivileged processes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries (CVE-2026-71225)&lt;/p&gt;
&lt;p&gt;* libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path (CVE-2026-71226)&lt;/p&gt;
&lt;p&gt;* libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return (CVE-2026-71227)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* libkcapi: AEAD Decrypt Auth Check Skipped for Zero-Length Input in `kcapi-enc` [rhel-9.8.z] (JIRA:Rocky Linux-242667)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:9: libkcapi&lt;/p&gt;
&lt;p&gt;libkcapi allows user-space to access the Linux kernel crypto API.  This library uses the netlink interface and exports easy to use APIs so that a developer does not need to consider the low-level netlink interface handling.  The library does not implement any cipher algorithms.  All consumer requests are sent to the kernel for processing.  Results from the kernel crypto API are returned to the consumer via the library API.  The kernel interface and therefore this library can be used by unprivileged processes.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries (CVE-2026-71225)&lt;/p&gt;
&lt;p&gt;* libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi&amp;#39;s one-shot AIO path (CVE-2026-71226)&lt;/p&gt;
&lt;p&gt;* libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return (CVE-2026-71227)&lt;/p&gt;
&lt;p&gt;Bug Fix(es) and Enhancement(s):&lt;/p&gt;
&lt;p&gt;* libkcapi: AEAD Decrypt Auth Check Skipped for Zero-Length Input in `kcapi-enc` [rhel-9.8.z] (JIRA:Rocky Linux-242667)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:67265</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-71227</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71227</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:FIPS:16.04:LTS: libkcapi, Ubuntu:18.04:LTS: libkcapi, Ubuntu:Pro:FIPS-updates:18.04:LTS: libkcapi, Ubuntu:Pro:FIPS:18.04:LTS: libkcapi, Ubuntu:20.04:LTS: libkcapi, Ubuntu:Pro:FIPS-updates:20.04:LTS: libkcapi, Ubuntu:Pro:FIPS:20.04:LTS: libkcapi, Ubuntu:22.04:LTS: libkcapi, Ubuntu:Pro:FIPS-preview:22.04:LTS: libkcapi, Ubuntu:Pro:FIPS-updates:22.04:LTS: libkcapi and 2 more&lt;/p&gt;
&lt;p&gt;A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:FIPS:16.04:LTS: libkcapi, Ubuntu:18.04:LTS: libkcapi, Ubuntu:Pro:FIPS-updates:18.04:LTS: libkcapi, Ubuntu:Pro:FIPS:18.04:LTS: libkcapi, Ubuntu:20.04:LTS: libkcapi, Ubuntu:Pro:FIPS-updates:20.04:LTS: libkcapi, Ubuntu:Pro:FIPS:20.04:LTS: libkcapi, Ubuntu:22.04:LTS: libkcapi, Ubuntu:Pro:FIPS-preview:22.04:LTS: libkcapi, Ubuntu:Pro:FIPS-updates:22.04:LTS: libkcapi and 2 more&lt;/p&gt;
&lt;p&gt;A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-71227</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3322 — Red Hat Enterprise Linux (libkcapi): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3322</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen, Daten zu manipulieren, Speicherbeschädigungen zu verursachen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux ausnutzen, um Informationen offenzulegen, Daten zu manipulieren, Speicherbeschädigungen zu verursachen oder einen Denial-of-Service-Zustand auszulösen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3322</guid>
    </item>
  </channel>
</rss>
