Skip to main content
EPSS 0.3%top 74%

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

0
Medium
Published: 08/19/2026 (08/19/2026, 13:15:02 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

A vulnerability in libkcapi affects one-shot symmetric cipher operations on large inputs over 64 KiB in stateful modes such as CTR or CBC. The library improperly reuses the Initialization Vector (IV) for each internal data chunk, weakening data confidentiality and potentially affecting data integrity. This issue impacts Red Hat Hardened Images RPMs including libkcapi versions 0.10.1 and 1.5.1-0.1.hum1. No official patch fix is currently indicated in the advisory, but mitigation involves avoiding one-shot symmetric cipher APIs for large inputs and using streaming interfaces instead.

Affected software

Affected versions
=0.10.1=1.5.1-0.1.hum1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/13/2026, 15:05:58 UTC

Technical Analysis

CVE-2026-71225 is a vulnerability in libkcapi where one-shot symmetric cipher operations on inputs larger than 64 KiB in stateful modes (e.g., CTR, CBC) reuse the Initialization Vector (IV) across internal data chunks. This IV reuse can expose relationships in encrypted plaintext, significantly weakening confidentiality and potentially causing incorrect cryptographic processing that affects integrity. The vulnerability affects Red Hat Hardened Images RPMs including libkcapi versions =0.10.1 and =1.5.1-0.1.hum1 on aarch64 and x86_64 architectures. Red Hat advises mitigating the issue by avoiding one-shot symmetric cipher APIs for large inputs and using streaming interfaces or ensuring inputs remain below the chunking threshold. There is no explicit mention of an official patch or fix released yet in the advisory.

Potential Impact

The vulnerability leads to significant weakening of data confidentiality due to IV reuse in cryptographic operations on large inputs, potentially exposing encrypted plaintext relationships. It may also affect data integrity by causing incorrect cryptographic processing. The attack complexity is high, no privileges or user interaction are required, and the attack vector is network-based. The CVSS v3.1 base score is 6.5 (medium severity) with high confidentiality impact and low integrity impact.

Mitigation Recommendations

Red Hat recommends that applications using libkcapi avoid one-shot symmetric cipher APIs for inputs exceeding 64 KiB when continuous-message semantics are critical. Instead, use the streaming interface for processing large messages or ensure one-shot inputs remain below the internal chunking threshold to guarantee consistent IV application. No official patch or update is currently indicated; check Red Hat advisories for updates. Follow vendor guidance and monitor for future fixes.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-qv62-qmw8-96h9
Osv Schema Version
1.4.0
Aliases
["CVE-2026-71225"]
Database Specific Severity
MODERATE
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a738529bf8831d5394f024a

Added to database: 08/05/2026, 18:47:05 UTC

Last enriched: 09/13/2026, 15:05:58 UTC

Last updated: 09/18/2026, 22:01:37 UTC

Views: 116

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses