Skip to content
Red HatCVE-2026-71227

Red Hat libkcapi: denial of service

Medium5.1CVE-2026-71227 · Published Aug 5, 2026 · updated Sep 21, 2026

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat OpenShift Container Platform 4
Product
all versionsNo fix yet
all versionsNo fix yet
libkcapi
Product
>= 0.12.0, < 1.5.11.5.1
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Enterprise Linux 10: integer overflow
Low2.2Aug 5
Red Hat RPM: buffer overflow
Medium5.5Aug 5
Red Hat OpenShift Container Platform 4: authentication bypass
Medium6.5Aug 5
Red Hat SAML broker: origin validation error
High7.4Aug 5
Red Hat Keycloak: type confusion
High8.8Aug 5
Red Hat LDAP storage provider of Keycloak: improper privilege management
Medium5.4Aug 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.