What is CVE-2026-71225?
CVE-2026-71225 is a vulnerability found in libkcapi, where 'one-shot' symmetric cipher operations on inputs over 64 KiB in stateful modes like CTR or CBC improperly reuse the Initialization Vector (IV) for each internal data chunk. This flaw could allow a remote attacker to break the encryption, so a security patch should be applied.
Azərbaycanca: CVE-2026-71225 libkcapi kitabxanasında tapılan bir zəiflikdir. Stateful rejimlərdə (CTR, CBC) 64 KiB-dən böyük məlumatlar üçün 'one-shot' simmetrik şifrələmə əməliyyatı zamanı Initialization Vector (IV) hər daxili data hissəsi üçün səhvən təkrar istifadə edilir, bu da uzaqdan hücum edənə şifrələməni qırmağa imkan verə bilər. Təhlükəsizlik yaması tətbiq edilməlidir.
FAQ2
In which library was CVE-2026-71225 discovered, and what operation does it affect?
This vulnerability was found in the libkcapi library and affects 'one-shot' symmetric cipher operations.
How is the Initialization Vector (IV) improperly used in the CVE-2026-71225 vulnerability?
For inputs larger than 64 KiB in stateful modes (CTR, CBC), the IV is mistakenly reused for each internal data chunk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.