CVE-2026-71227
Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
CVSS Score
5.1
EPSS Score
0.0%
EPSS Percentile
0th
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.
| CWE | CWE-835 |
| Vendor | stephan muelle |
| Product | libkcapi |
| Published | Aug 5, 2026 |
| Last Updated | Sep 14, 2026 |
Stay Ahead of the Next One
Get instant alerts for stephan muelle libkcapi
Be the first to know when new medium vulnerabilities affecting stephan muelle libkcapi are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
Stephan Muelle / libkcapi
0.12.0 < 1.5.1
Red Hat / Red Hat Enterprise Linux 10
All versions affected Red Hat / Red Hat Enterprise Linux 8
All versions affected Red Hat / Red Hat Enterprise Linux 9
All versions affected Red Hat / Red Hat Hardened Images
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected Red Hat / Red Hat OpenShift Container Platform 4
All versions affected References
access.redhat.com: https://access.redhat.com/errata/RHSA-2026:56985 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:67265 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:67266 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:67267 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-71227 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2462867
Credits
This issue was discovered by Found by AISLE in partnership with Red Hat.