AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-71227

MEDIUM · CVSS 5.1 EPSS 0.11%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability in libkcapi allows local attackers to exploit the Asynchronous Input/Output (AIO) interface by reusing an AIO-enabled handle after a completion error. This can cause the _kcapi_aio_read_all() function to enter a non-terminating wait loop, resulting in a persistent denial of service that renders the affected application or thread unresponsive. Organizations using libkcapi in their applications should prioritize addressing this issue to mitigate potential service disruptions.

CVE
CVE-2026-71227
Severity
MEDIUM
CVSS
5.1
EPSS
0.11%

Original NVD Description

A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.

Related CVEs

Other vulnerabilities affecting the same vendor(s)