A flaw was found in libkcapi. A local attacker can...
Moderate severity
Unreviewed
Published
Aug 5, 2026
to the GitHub Advisory Database
•
Updated Aug 19, 2026
Description
Published by the National Vulnerability Database
Aug 5, 2026
Published to the GitHub Advisory Database
Aug 5, 2026
Last updated
Aug 19, 2026
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of service, making the affected application or thread unresponsive.
References