CVE-2026-71226
7.3
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Exploitability: 2.5 / Impact: 4.7
Source: NVD
Description
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
Affected (6)
Products: Redhat: Enterprise Linux, Hardened Images, Openshift Container Platform · Smuellerdd: Libkcapi
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 | |
| All versions | |
| Version 4.0 | |
| From 0.12.0 to 1.5.1 |
References (3)
Source: secalert@redhat.com
Source: secalert@redhat.com
Issue TrackingVendor Advisory
Timeline
No history available yet.