Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
A vulnerability in libkcapi affects one-shot symmetric cipher operations on large inputs over 64 KiB in stateful modes such as CTR or CBC. The library improperly reuses the Initialization Vector (IV) for each internal data chunk, weakening data confidentiality and potentially affecting data integrity. This issue impacts Red Hat Hardened Images RPMs including libkcapi versions 0.10.1 and 1.5.1-0.1.hum1. No official patch fix is currently indicated in the advisory, but mitigation involves avoiding one-shot symmetric cipher APIs for large inputs and using streaming interfaces instead.
AI Analysis
Technical Summary
CVE-2026-71225 is a vulnerability in libkcapi where one-shot symmetric cipher operations on inputs larger than 64 KiB in stateful modes (e.g., CTR, CBC) reuse the Initialization Vector (IV) across internal data chunks. This IV reuse can expose relationships in encrypted plaintext, significantly weakening confidentiality and potentially causing incorrect cryptographic processing that affects integrity. The vulnerability affects Red Hat Hardened Images RPMs including libkcapi versions =0.10.1 and =1.5.1-0.1.hum1 on aarch64 and x86_64 architectures. Red Hat advises mitigating the issue by avoiding one-shot symmetric cipher APIs for large inputs and using streaming interfaces or ensuring inputs remain below the chunking threshold. There is no explicit mention of an official patch or fix released yet in the advisory.
Potential Impact
The vulnerability leads to significant weakening of data confidentiality due to IV reuse in cryptographic operations on large inputs, potentially exposing encrypted plaintext relationships. It may also affect data integrity by causing incorrect cryptographic processing. The attack complexity is high, no privileges or user interaction are required, and the attack vector is network-based. The CVSS v3.1 base score is 6.5 (medium severity) with high confidentiality impact and low integrity impact.
Mitigation Recommendations
Red Hat recommends that applications using libkcapi avoid one-shot symmetric cipher APIs for inputs exceeding 64 KiB when continuous-message semantics are critical. Instead, use the streaming interface for processing large messages or ensure one-shot inputs remain below the internal chunking threshold to guarantee consistent IV application. No official patch or update is currently indicated; check Red Hat advisories for updates. Follow vendor guidance and monitor for future fixes.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
A vulnerability in libkcapi affects one-shot symmetric cipher operations on large inputs over 64 KiB in stateful modes such as CTR or CBC. The library improperly reuses the Initialization Vector (IV) for each internal data chunk, weakening data confidentiality and potentially affecting data integrity. This issue impacts Red Hat Hardened Images RPMs including libkcapi versions 0.10.1 and 1.5.1-0.1.hum1. No official patch fix is currently indicated in the advisory, but mitigation involves avoiding one-shot symmetric cipher APIs for large inputs and using streaming interfaces instead.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-71225 is a vulnerability in libkcapi where one-shot symmetric cipher operations on inputs larger than 64 KiB in stateful modes (e.g., CTR, CBC) reuse the Initialization Vector (IV) across internal data chunks. This IV reuse can expose relationships in encrypted plaintext, significantly weakening confidentiality and potentially causing incorrect cryptographic processing that affects integrity. The vulnerability affects Red Hat Hardened Images RPMs including libkcapi versions =0.10.1 and =1.5.1-0.1.hum1 on aarch64 and x86_64 architectures. Red Hat advises mitigating the issue by avoiding one-shot symmetric cipher APIs for large inputs and using streaming interfaces or ensuring inputs remain below the chunking threshold. There is no explicit mention of an official patch or fix released yet in the advisory.
Potential Impact
The vulnerability leads to significant weakening of data confidentiality due to IV reuse in cryptographic operations on large inputs, potentially exposing encrypted plaintext relationships. It may also affect data integrity by causing incorrect cryptographic processing. The attack complexity is high, no privileges or user interaction are required, and the attack vector is network-based. The CVSS v3.1 base score is 6.5 (medium severity) with high confidentiality impact and low integrity impact.
Mitigation Recommendations
Red Hat recommends that applications using libkcapi avoid one-shot symmetric cipher APIs for inputs exceeding 64 KiB when continuous-message semantics are critical. Instead, use the streaming interface for processing large messages or ensure one-shot inputs remain below the internal chunking threshold to guarantee consistent IV application. No official patch or update is currently indicated; check Red Hat advisories for updates. Follow vendor guidance and monitor for future fixes.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-qv62-qmw8-96h9
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-71225"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a738529bf8831d5394f024a
Added to database: 08/05/2026, 18:47:05 UTC
Last enriched: 09/13/2026, 15:05:58 UTC
Last updated: 09/18/2026, 22:01:37 UTC
Views: 116
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.