A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. (CVE-2026-71227)
A vulnerability in libkcapi allows a local attacker to cause a denial of service by triggering an infinite wait loop in the _kcapi_aio_read_all() function when reusing an AIO-enabled handle after a prior completion error. This flaw affects applications using the Asynchronous Input/Output (AIO) interface and can make the affected application or thread unresponsive.
AI Analysis
Technical Summary
CVE-2026-71227 is a denial of service vulnerability in libkcapi related to the Asynchronous Input/Output (AIO) interface. When an application reuses an AIO-enabled handle after a previous completion error, the _kcapi_aio_read_all() function may enter a non-terminating wait loop due to unhandled io_getevents() timeout returns. This infinite loop causes persistent denial of service by making the application or thread unresponsive. The vulnerability is classified under CWE-835 (Loop with Unreachable Exit Condition).
Potential Impact
The vulnerability leads to a persistent denial of service condition by causing an infinite loop that consumes CPU resources, making the affected application or thread unresponsive. There is no impact on confidentiality or integrity, but availability is severely affected.
Mitigation Recommendations
To mitigate this issue, applications should avoid initializing libkcapi handles with KCAPI_INIT_AIO unless AIO functionality is strictly required. If AIO must be used, applications should destroy and reinitialize libkcapi handles after any AIO completion error instead of reusing them for subsequent operations. No official patch is currently referenced; patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. (CVE-2026-71227)
Description
A vulnerability in libkcapi allows a local attacker to cause a denial of service by triggering an infinite wait loop in the _kcapi_aio_read_all() function when reusing an AIO-enabled handle after a prior completion error. This flaw affects applications using the Asynchronous Input/Output (AIO) interface and can make the affected application or thread unresponsive.
CVSS v3.1
Score 5.1medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-71227 is a denial of service vulnerability in libkcapi related to the Asynchronous Input/Output (AIO) interface. When an application reuses an AIO-enabled handle after a previous completion error, the _kcapi_aio_read_all() function may enter a non-terminating wait loop due to unhandled io_getevents() timeout returns. This infinite loop causes persistent denial of service by making the application or thread unresponsive. The vulnerability is classified under CWE-835 (Loop with Unreachable Exit Condition).
Potential Impact
The vulnerability leads to a persistent denial of service condition by causing an infinite loop that consumes CPU resources, making the affected application or thread unresponsive. There is no impact on confidentiality or integrity, but availability is severely affected.
Mitigation Recommendations
To mitigate this issue, applications should avoid initializing libkcapi handles with KCAPI_INIT_AIO unless AIO functionality is strictly required. If AIO must be used, applications should destroy and reinitialize libkcapi handles after any AIO completion error instead of reusing them for subsequent operations. No official patch is currently referenced; patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-c5mv-c5vm-62w5
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-71227"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a738527bf8831d5394f01c4
Added to database: 08/05/2026, 18:47:03 UTC
Last enriched: 08/05/2026, 22:04:01 UTC
Last updated: 08/06/2026, 03:40:59 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.