CVE-2026-71227: Red Hat Enterprise Linux
Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.
Affected products
- Red Hat Enterprise Linux: version 8.0 only; version 9.0 only; version 10.0 only
- Red Hat Hardened Images: affected versions not specified
- Red Hat Openshift Container Platform: version 4.0 only
- Smuellerdd Libkcapi: from 0.12.0, before 1.5.1 (fixed in 1.5.1)
Published 2026-08-05. Last modified 2026-09-21.