access.redhat.comvdb entry
https://access.redhat.com/security/cve/CVE-2026-71226 CVE-2026-71226
HIGH
Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path
Record summary
CVE-2026-71226 has a selected CVSS score of 7.3 (high).
Description
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 5, 2026 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
Default status: affected | CVE List | Version data not supplied | |
libkcapiBrowse Stephan Muelle / libkcapiDefault status: unaffected | CVE List | 0.12.0 to < 1.5.1 | affected |
References
3RHBZ#2462114issue tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2462114 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-71226