Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-71225— Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries

Quick assessment

Affected
Stephan Muelle libkcapi
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

chronox.de libkcapi是chronox.de团队的一个加密API组件库。 chronox.de libkcapi存在加密问题漏洞,该漏洞源于在CTR或CBC等状态模式下对超过64 KiB的大型输入执行一次性对称密码操作时,不当重用初始化向量(IV),远程攻击者可能利用此漏洞使应用程序处理特制大型输入,导致数据机密性削弱并可能影响数据完整性。

CVSS 6.5 · Medium EPSS 0.52% · P42

Possible ATT&CK Techniques 1 AI

T1557 · Adversary-in-the-Middle

Affected Version Matrix 8

VendorProduct Version RangeStatus
Red Hat Red Hat Enterprise Linux 10 0:1.5.1-1.el10_2< * unaffected
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:1.5.0-6.el10_0< * unaffected
Red Hat Red Hat Enterprise Linux 8 0:1.4.0-3.el8_10< * unaffected
Red Hat Red Hat Enterprise Linux 9 0:1.4.0-3.el9_8< * unaffected
Red Hat Red Hat Hardened Images 1.5.1-0.1.hum1< * unaffected
Red Hat Red Hat OpenShift Container Platform 4 any affected
any affected
Stephan Muelle libkcapi 0.10.1< 1.5.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-71225

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Libkcapi: iv reuse in libkcapi one-shot symmetric cipher chunking causes cipher state reset across chunk boundaries
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit this by making an application that uses libkcapi process specially crafted large inputs. This can lead to a significant weakening of data confidentiality, as the repeated IV use can expose relationships in encrypted plaintext, and may also affect data integrity by causing incorrect cryptographic processing.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用不充分的随机数
Source: CVE Program / CVE List V5
Vulnerability Title
chronox.de libkcapi 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
chronox.de libkcapi是chronox.de团队的一个加密API组件库。 chronox.de libkcapi存在加密问题漏洞,该漏洞源于在CTR或CBC等状态模式下对超过64 KiB的大型输入执行一次性对称密码操作时,不当重用初始化向量(IV),远程攻击者可能利用此漏洞使应用程序处理特制大型输入,导致数据机密性削弱并可能影响数据完整性。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Stephan Muelle libkcapi 0.10.1 ~ 1.5.1 -
Red Hat Red Hat Enterprise Linux 10 0:1.5.1-1.el10_2 ~ * cpe:/o:redhat:enterprise_linux:10.2
Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support 0:1.5.0-6.el10_0 ~ * cpe:/o:redhat:enterprise_linux_eus:10.0
Red Hat Red Hat Enterprise Linux 8 0:1.4.0-3.el8_10 ~ * cpe:/o:redhat:enterprise_linux:8::baseos
Red Hat Red Hat Enterprise Linux 9 0:1.4.0-3.el9_8 ~ * cpe:/o:redhat:enterprise_linux:9::baseos
Red Hat Red Hat Hardened Images 1.5.1-0.1.hum1 ~ * cpe:/a:redhat:hummingbird:1
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4
Red Hat Red Hat OpenShift Container Platform 4 - cpe:/a:redhat:openshift:4

II. Public POCs for CVE-2026-71225

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-71225

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-71225 (7)

Same Patch Batch · Stephan Muelle · 2026-08-05 · 3 CVEs total

CVE-2026-71226 7.3 HIGH Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot ai
CVE-2026-71227 5.1 MEDIUM Libkcapi: infinite loop denial of service in libkcapi _kcapi_aio_read_all() due to unhandl

IV. Related Vulnerabilities

V. Comments for CVE-2026-71225

No comments yet


Leave a comment