[CLSA-2026:1786699908] libkcapi: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-14 09:31:59 UTC
Description:
- CVE-2026-71225: stop resending ALG_SET_IV for every 64 KiB chunk of a one-shot symmetric cipher operation, which reused the IV in CTR and CBC - CVE-2026-71226: reap all submitted AIO requests before returning an error so the kernel cannot write into output buffers the caller has released - CVE-2026-71227: report a zero io_getevents() return as -ETIMEDOUT so _kcapi_aio_read_all() cannot spin forever on a reused AIO handle
Updated packages:
  • libkcapi-1.4.0-3.el9_6.tuxcare.els1.i686.rpm
    sha:527b60dbf4525bcf4eb37fd8b566160c7efbbfa38d47a374d3653940c617f787
  • libkcapi-1.4.0-3.el9_6.tuxcare.els1.x86_64.rpm
    sha:4f61eac198b202b0f404322ffae8fc110076ff62223a2fb6cc2b80da60bda294
  • libkcapi-devel-1.4.0-3.el9_6.tuxcare.els1.x86_64.rpm
    sha:2164e903527253b489f8a0c75785a71f5694f0fbe84b4c9dd1f13dca1b96a7fa
  • libkcapi-doc-1.4.0-3.el9_6.tuxcare.els1.noarch.rpm
    sha:1dfd9dbd2e1b6e21cf04efe9284c415d9119f36ed0cdea14b4983086d7d4db18
  • libkcapi-fipscheck-1.4.0-3.el9_6.tuxcare.els1.x86_64.rpm
    sha:fa446249593e784a8169c4eb55916cd09838d3e00b0fdf8a3bcb3e9a89206dfd
  • libkcapi-hmaccalc-1.4.0-3.el9_6.tuxcare.els1.x86_64.rpm
    sha:371e8e5a5481cd8bedeabc18727926c09188c5a5c56bf389c13bb0361185df81
  • libkcapi-static-1.4.0-3.el9_6.tuxcare.els1.x86_64.rpm
    sha:1e7794a789f8865eb82cbdb9e6ee5ffe66fad6ee7f04b5a4c55972873ba1b26f
  • libkcapi-tests-1.4.0-3.el9_6.tuxcare.els1.x86_64.rpm
    sha:e088d0cf7d0e993de24ce617cb2ea3a05e30854fdce5dcf41dfe4fee7faaf148
  • libkcapi-tools-1.4.0-3.el9_6.tuxcare.els1.x86_64.rpm
    sha:8235dc472e87f3576efba9d58c4a009e2c99df9f9594989ef83c24d1e24b30eb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.