PT-2026-68129 · Libkcapi · Libkcapi

·

CVE-2026-71225

·

Published

2026-08-05

·

Updated

2026-08-30

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions libkcapi (affected versions not specified)
Description A flaw exists when performing one-shot symmetric cipher operations on inputs exceeding 64 KiB in stateful modes, specifically Counter (CTR) or Cipher Block Chaining (CBC). The library improperly reuses the Initialization Vector (IV)—a random or pseudo-random value used to ensure that the same plaintext encrypts to different ciphertexts—for each internal data chunk. A remote attacker could exploit this by inducing an application to process specially crafted large inputs, leading to weakened data confidentiality by exposing relationships in encrypted plaintext and potentially compromising data integrity through incorrect cryptographic processing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-94655
CVE-2026-71225
OESA-2026-3575
RHSA-2026:56985

Affected Products

Libkcapi