Red Hat Security Advisory: libkcapi security, bug fix, and enhancement update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-71225 — libkcapi: IV reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries CVE-2026-71226 — libkcapi: Memory corruption via uncanceled AIO requests on error in libkcapi's one-shot AIO path CVE-2026-71227 — libkcapi: Infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandled io_getevents() timeout return
🎯 Affected products41
- Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-0:1.4.0-3.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-0:1.4.0-3.el9_8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-0:1.4.0-3.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-0:1.4.0-3.el9_8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-0:1.4.0-3.el9_8.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-0:1.4.0-3.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-debuginfo-0:1.4.0-3.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-debuginfo-0:1.4.0-3.el9_8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-debuginfo-0:1.4.0-3.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-debuginfo-0:1.4.0-3.el9_8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-debuginfo-0:1.4.0-3.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-debugsource-0:1.4.0-3.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-debugsource-0:1.4.0-3.el9_8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-debugsource-0:1.4.0-3.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-debugsource-0:1.4.0-3.el9_8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-debugsource-0:1.4.0-3.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-fipscheck-debuginfo-0:1.4.0-3.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-fipscheck-debuginfo-0:1.4.0-3.el9_8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-fipscheck-debuginfo-0:1.4.0-3.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-fipscheck-debuginfo-0:1.4.0-3.el9_8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-fipscheck-debuginfo-0:1.4.0-3.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-hmaccalc-0:1.4.0-3.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-hmaccalc-0:1.4.0-3.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-hmaccalc-0:1.4.0-3.el9_8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-hmaccalc-0:1.4.0-3.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-hmaccalc-debuginfo-0:1.4.0-3.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-hmaccalc-debuginfo-0:1.4.0-3.el9_8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-hmaccalc-debuginfo-0:1.4.0-3.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- libkcapi-hmaccalc-debuginfo-0:1.4.0-3.el9_8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- +11 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, applications using `libkcapi` should avoid the one-shot symmetric cipher APIs for inputs exceeding 64 KiB when continuous-message semantics are critical. Instead, prefer the streaming interface for processing large messages, or ensure one-shot inputs remain below the internal chunking threshold to guarantee the IV is applied consistently throughout the operation. Workaround: To mitigate this issue, applications should avoid initializing libkcapi handles with the `KCAPI_INIT_AIO` flag, preferring synchronous interfaces instead. If the real AIO path must be enabled, applications must ensure that `outiov` buffers are not immediately freed or reused after an error return, allowing all kernel completions to finish. This operational control prevents delayed kernel writes into potentially reallocated or freed memory. Workaround: To mitigate this issue, applications should avoid initializing `libkcapi` handles with `KCAPI_INIT_AIO` if AIO functionality is not strictly required. If AIO must be used, applications should destroy and reinitialize `libkcapi` handles after any AIO completion error, rather than reusing them for subsequent AIO operations.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:67265
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2462011
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2462114
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2462867
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_67265.json