Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
5.1
CVE-2026-71227
- EPSS 0.13%
- Veröffentlicht 05.08.2026 12:42:10
- Zuletzt bearbeitet 19.08.2026 21:17:36
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-t...
7.3
CVE-2026-71226
- EPSS 0.13%
- Veröffentlicht 05.08.2026 12:37:17
- Zuletzt bearbeitet 19.08.2026 21:17:36
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
6.5
CVE-2026-71225
- EPSS 0.3%
- Veröffentlicht 05.08.2026 12:16:52
- Zuletzt bearbeitet 19.08.2026 21:17:35
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for ...
1