PT-2026-68129 · Libkcapi · Libkcapi
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
libkcapi (affected versions not specified)
Description
A flaw exists when performing one-shot symmetric cipher operations on inputs exceeding 64 KiB in stateful modes, specifically Counter (CTR) or Cipher Block Chaining (CBC). The library improperly reuses the Initialization Vector (IV)—a random or pseudo-random value used to ensure that the same plaintext encrypts to different ciphertexts—for each internal data chunk. A remote attacker could exploit this by inducing an application to process specially crafted large inputs, leading to weakened data confidentiality by exposing relationships in encrypted plaintext and potentially compromising data integrity through incorrect cryptographic processing.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libkcapi