What is CVE-2026-71227?
A vulnerability in libkcapi allows a local attacker to influence applications using the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop, potentially leading to a persistent denial of service. Systems using libkcapi should be updated.
Azərbaycanca: libkcapi kitabxanasında aşkar edilmiş bu boşluq yerli təcavüzkara Asinxron Giriş/Çıxış (AIO) interfeysindən istifadə edən tətbiqə təsir etməyə imkan verir. AIO aktiv handle səhv tamamlandıqdan sonra təkrar istifadə edilərsə, _kcapi_aio_read_all() funksiyası sonsuz gözləmə dövrünə girərək xidmətin dayanmasına səbəb ola bilər. libkcapi-dən istifadə edən sistemləri yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
In which library was CVE-2026-71227 discovered, and which interface does it affect?
This vulnerability was discovered in the libkcapi library and affects applications using the Asynchronous Input/Output (AIO) interface.
How can CVE-2026-71227 be exploited and what is the result?
A local attacker can reuse an AIO-enabled handle after a prior completion error, causing the _kcapi_aio_read_all() function to enter a non-terminating wait loop, potentially leading to a denial of service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.