AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-71226

HIGH · CVSS 7.3 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-08-05 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A memory corruption vulnerability exists in libkcapi due to uncanceled asynchronous I/O (AIO) requests, which can lead to kernel writes into user-controlled output buffers when errors occur before all I/O control blocks (IOCBs) are processed. This flaw poses a high risk as it could be exploited to execute arbitrary code or cause system instability. Organizations utilizing libkcapi in their applications should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-71226
Severity
HIGH
CVSS
7.3
EPSS
0.12%

Original NVD Description

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

Related CVEs

Other vulnerabilities affecting the same vendor(s)