Red Hat libkcapi.: weak randomness
Medium6.5CVE-2026-71225 · Published Aug 5, 2026 · updated Sep 21, 2026
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat OpenShift Container Platform 4 Product | all versions | No fix yet |
| all versions | No fix yet | |
| libkcapi Product | >= 0.10.1, < 1.5.1 | 1.5.1 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-330
- www.cve.org/CVERecord?id=CVE-2026-71225
- nvd.nist.gov/vuln/detail/CVE-2026-71225
- access.redhat.com/errata/RHSA-2026:56985
- access.redhat.com/errata/RHSA-2026:67265
- access.redhat.com/errata/RHSA-2026:67266
- access.redhat.com/errata/RHSA-2026:67267
- access.redhat.com/errata/RHSA-2026:69285
- access.redhat.com/security/cve/CVE-2026-71225
- bugzilla.redhat.com/show_bug.cgi?id=2462011
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 5 | Red Hat Enterprise Linux 10: integer overflow | Low2.2 | No fix yet |
| Aug 5 | Red Hat RPM: buffer overflow | Medium5.5 | No fix yet |
| Aug 5 | Red Hat OpenShift Container Platform 4: authentication bypass | Medium6.5 | No fix yet |
| Aug 5 | Red Hat SAML broker: origin validation error | High7.4 | No fix yet |
| Aug 5 | Red Hat Keycloak: type confusion | High8.8 | No fix yet |
| Aug 5 | Red Hat LDAP storage provider of Keycloak: improper privilege management | Medium5.4 | No fix yet |